Pegasus spyware hits Serbian students and politicians in zero-click attack
It’s the largest documented surveillance wave in Serbia to date.

Pegasus spyware. Image by Reuters
- At least 14 people in Serbia were targeted with Pegasus spyware during local elections in early 2026.
- Targets included student movement members, activists, an opposition parliament member, and a local opposition councilor.
- Investigators found attackers used an iMessage zero-click exploit, infecting phones without user action.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
At least 14 people in Serbia were targeted with Pegasus spyware in early 2026, when local elections were being held.
Pegasus, which was created by the Israeli company NSO Group, is spyware that can turn any smartphone into a spying device that monitors its owner 24/7.
The spyware intercepts all digital communications, from emails to text messages and WhatsApp messages. It can also download photos and videos, steal contacts’ phone numbers, secretly record videos, and eavesdrop on phone calls.
To top it off, Pegasus keeps track of the phone owner’s exact location.
What makes Pegasus particularly dangerous is that it’s extremely difficult to detect and can steal sensitive information without the victim having to do anything. This is called a zero-click attack.
In August, 12 people contacted the SHARE Foundation after receiving an Apple threat notification warning that their iPhones had been targeted in a spyware attack. Analysis later confirmed 2 more infections.
Those targeted include members of the student movement, activists, a member of the Serbian national parliament, and a local councilor, all from opposition parties.
The attackers used an iMessage zero-click exploit to infect the devices with surveillance software. This means that the device was infected remotely, without any knowledge or interaction by the user.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The vulnerability used for the zero-click exploit was fixed by Apple in iOS 18.4.1, a patch that was released in April 2025.
The University of Toronto’s Citizen Lab and Amnesty International’s Security Lab independently confirmed that the victims’ phones were infected with Pegasus spyware.
The SHARE Foundation’s security researchers urge users to keep their smartphones up to date, avoid content from unknown sources, and ignore suspicious links.
People who are at higher risk, such as human rights activists, journalists, academics, and politicians in authoritarian regimes, are advised to enable advanced security features, including Lockdown Mode for iOS and Advanced Protection for Android devices.