Decoding the world of cybersecurity

Pegasus found on Serbian protest activist’s iPhone

Citizen Lab has forensically confirmed Pegasus spyware on a Serbian student activist’s iPhone after an iMessage zero-click attack, while the identity of the operator remains unknown.

Pegasus found on Serbian protest activist’s iPhone
Summary
  • Citizen Lab confirmed Pegasus infection artefacts on the iPhone of a member of Serbia’s student protest movement.
  • Researchers assess that an iMessage zero-click exploit was used during a period spanning December 2025 and January 2026.
  • The spyware operator has not been identified, despite a wider wave of Apple threat notifications affecting Serbian civil society.

Citizen Lab has confirmed that an unnamed member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware, adding a new forensically verified case to the continuing use of commercial surveillance tools against European civil society.

The Toronto-based research group analysed the activist’s iPhone with Serbia’s SHARE Foundation after the user received an Apple threat notification warning that the device had been targeted with mercenary spyware. Citizen Lab said forensic artefacts showed a Pegasus infection during a period spanning December 2025 and January 2026.

Researchers assess that the infection used a zero-click exploit targeting Apple’s iMessage service. A zero-click attack does not require the target to open a malicious attachment, follow a link, or approve a prompt, removing many of the behavioural signals associated with conventional phishing.

Citizen Lab said the exploit involved in the case has subsequently been rendered ineffective by an Apple patch released with iOS 18.4.1. The researchers did not publish the precise infection time, partly to protect the activist’s privacy.

The identity of the Pegasus operator has not been established. The forensic finding confirms that the device was infected with the NSO Group spyware, but it does not by itself identify the government agency, organisation, or individuals responsible for deploying it.

That boundary is particularly important in Serbia, where surveillance technology has already become an issue of political and institutional accountability. Citizen Lab and SHARE Foundation said at least 14 people connected to the country’s student movement, civil society, and political opposition have received Apple threat notifications in the latest wave. A notification indicates suspected mercenary-spyware targeting, but it is not equivalent to a forensic confirmation that every notified device was successfully compromised.

Pegasus is designed to provide extensive access to a compromised device, potentially including messages, photographs, files, microphone and camera functions, and other information available to the user. The sensitivity of such access means the consequences extend well beyond conventional endpoint compromise when targets are activists, politicians, lawyers, journalists, or others handling confidential communications.

The Serbian case also illustrates the continuing gap between platform-level security improvements and the market for targeted surveillance. Apple and other device makers have repeatedly hardened their operating systems against exploit chains used by commercial spyware operators, while researchers continue to document new or previously undisclosed compromises.

That dynamic has pushed mercenary spyware into a wider European policy debate concerning export controls, government procurement, lawful interception, vulnerability exploitation, and the safeguards applied when powerful surveillance capabilities are purchased from private suppliers.

Forensic attribution remains difficult by design. Establishing that Pegasus was installed is a technical finding; identifying who selected the target and authorised the operation is a separate evidential and political question. Citizen Lab has not made that attribution in this case.

The research organisation said its investigation of the wider group of Serbian notifications is continuing. Further forensic results could establish whether the confirmed Pegasus infection was an isolated success within a wider targeting campaign or one example of a broader set of compromises.

×