Citizen Lab Confirms Pegasus and a New NoviSpy Variant on Serbian Activists' Phones
Citizen Lab and the SHARE Foundation confirmed Pegasus and a new NoviSpy variant on the phones of Serbian student activists. It is the first forensically confirmed Pegasus infection of 2026 and, the SHARE Foundation says, the biggest spyware wave in Serbia yet.
Researchers have confirmed the first forensically verified Pegasus spyware infection of 2026, on the iPhone of a member of Serbia’s student protest movement, in what digital-rights investigators call the largest documented wave of that kind of surveillance the country has seen. The University of Toronto’s Citizen Lab, working with the Belgrade-based SHARE Foundation, confirmed the NSO Group Pegasus infection with high confidence. Amnesty International separately confirmed a new variant of the Android spyware known as NoviSpy on the phones of student-movement members. CyberScoop first reported the findings on September 2, 2026.
The scale is what sets this apart from earlier Serbian cases. SHARE says it has documented at least 14 people who received Apple Threat Notifications warning of mercenary-spyware targeting, including an opposition member of parliament and a local government official. Three of those devices have so far been forensically confirmed as infected: one with Pegasus, two with the new NoviSpy variant. The rest are, for now, confirmed targets rather than confirmed infections, and that distinction runs through everything below.
What Citizen Lab and SHARE Actually Confirmed
Citizen Lab’s core finding is narrow and specific: an iMessage zero-click exploit was used to plant NSO Group’s Pegasus on one activist’s iPhone, with high-confidence indicators of infection across December 2025 to January 2026. A zero-click attack needs no tap, no link, and no mistake by the target. The device is compromised silently, and the operator gains total access, from notes and photos to the microphone, camera, and encrypted messages. Citizen Lab says the specific exploit has since been closed by Apple, as of iOS 18.4.1. The lab is not naming the activist, who asked to remain unidentified, and neither are we.
That Pegasus case rode a zero-click exploit of a then-unpatched flaw, the kind of zero-day exploit that commercial spyware brokers pay millions to acquire. The value comes from stealth: because no patch exists at the moment of use, the exploit works reliably and leaves the target with nothing to click and nothing to notice. It is the same profile Citizen Lab has documented against Pegasus targets for a decade.
The reporting distinction is where this piece earns its place. A headline number like “14 targeted” blends two very different things: people whom Apple warned were in the crosshairs, and devices where forensic analysis actually recovered spyware. SHARE and Citizen Lab have been careful to separate them, and Citizen Lab’s own guidance is that an Apple Threat Notification should be treated as presumed infection until an expert says otherwise. For a defender, that framing is the useful one: you plan around presumed compromise, not around a confirmed count that will keep changing as analysis continues.
The “first of 2026” framing is worth reading precisely. It does not mean Pegasus went quiet this year; it means this is the first 2026 infection Citizen Lab has been able to confirm through hands-on forensic analysis of a device, a much higher bar than a suspicion or a network signature. Confirmed cases lag real activity, because they depend on a target coming forward, consenting to analysis, and preserving a phone long enough for a lab to examine it. Treat this wave as a floor on the problem in Serbia, not a ceiling.
NoviSpy: Spyware Tied to Detention
The NoviSpy side of the wave points somewhere more specific. One NoviSpy variant infection, SHARE says, came after authorities took a student’s phone during police questioning, and the same spyware turned up on a second device after that phone’s private messages were published by a media outlet aligned with the ruling party. Both SHARE and Amnesty International assess that Serbian police or the security service are behind the NoviSpy cases, based on the pattern of infection during detention.
“These new forensic findings show that Serbian student activists continue to be targeted with invasive spyware,” Donncha Ó Cearbhaill, head of Amnesty International’s Security Lab, told CyberScoop, adding that the evidence suggests the infections were carried out during detention by the Serbian authorities. That echoes Amnesty’s December 2024 report documenting NoviSpy planted with the help of Cellebrite forensic tools.
Two flags belong on the attribution. First, the link to Serbian police or the security service is an assessment by SHARE and Amnesty from the circumstances, not a proven, agency-named finding. Second, the Pegasus case is even less resolved: investigators rarely determine which specific government operated Pegasus in a given infection, and this wave is no exception. So the honest statement is that a Serbian state nexus is strongly indicated for the NoviSpy cases and unproven as to who ran Pegasus.
Why Now: Elections and a Protest Movement
The timing tracks Serbia’s political calendar. The student movement grew out of the November 2024 collapse of a railway station canopy in Novi Sad that killed 15 people, an event that fed months of anti-corruption protests. SHARE says the spyware activity coincided with the build-up to local elections held in March across a set of municipalities, widely read as a test of the ruling Serbian Progressive Party, and it lands ahead of parliamentary elections expected in October. Civil society keeps ending up in the blast radius of state surveillance tooling, from a Russian operation that turned one Signal hijack into a 13,500-target map to repeated Pegasus abuse across Europe.
The wave surfaced because Apple told the targets. The company sent threat notifications to affected users in an August round that investigators described as unusually large, and those alerts are what sent activists to SHARE and Citizen Lab for forensic screening in the first place.
What NSO Group Says
NSO Group did respond, with its standard position: the company maintains that Pegasus is licensed to government clients for use against terrorism and serious crime, and that it shuts down any abuses it identifies. NSO did not identify the operator in the Serbian case. Citizen Lab is unpersuaded by the reform narrative. Its senior researcher John Scott-Railton drew a line from the very first Pegasus discovery a decade ago, against the UAE activist Ahmed Mansoor, to this one: “NSO spent a decade promising reform, yet their spyware is still an instrument of political repression.”
This is the pattern the mercenary-spyware market keeps producing. A vendor sells a government a capability marketed for terrorists and criminals, and forensic evidence keeps surfacing it on the phones of students, journalists, and opposition politicians. The recurrence is the story as much as any single infection, which is also why a well-worn defensive playbook exists.
What At-Risk Users and Organizations Should Do
For anyone whose work makes them a plausible spyware target (human-rights defenders, journalists, opposition figures, and the organizations that support them), the defensive steps are established and, frankly, under-used. They will not stop a determined state operator with a fresh zero-day forever, but they raise cost, close known exploit paths, and turn a silent compromise into something you can detect and respond to.
● PROTECTIVE STEPS FOR AT-RISK USERS If who you are or what you do makes you a spyware target, these controls are the established playbook. Defensive only. |
1 · TURN ON LOCKDOWN MODE Apple’s Lockdown Mode hardens iMessage, web browsing, and other zero-click surfaces on iPhone and Mac. Citizen Lab urges at-risk users to enable it. |
2 · KEEP EVERY DEVICE UPDATED The iMessage exploit in this case was closed in iOS 18.4.1. Running the latest iOS, iPadOS, and macOS shuts known zero-click paths as vendors patch them. |
3 · SCREEN DEVICES WITH TRUSTED TOOLS Amnesty’s Mobile Verification Toolkit (MVT) and iVerify can surface indicators of Pegasus and similar spyware. Run checks on a schedule, not just after an alert. |
4 · SHRINK THE ATTACK SURFACE Fewer messaging apps, disabled link previews, and a separate device for sensitive work all reduce the zero-click surface an operator can reach. |
GOT AN APPLE THREAT NOTIFICATION? TREAT THE DEVICE AS INFECTED Do not wipe or reset it first. Preserve the device and seek expert help: Access Now’s Digital Security Helpline, or Citizen Lab, can guide forensic screening and next steps. |
Guidance: Citizen Lab spyware response resources and Access Now’s Apple Threat Notification FAQ. Defensive steps only. |
Checklist: at-risk-user hardening and response steps, drawn from Citizen Lab and Access Now guidance.
For a security team that supports civil society, the operational takeaway is simple. Treat an Apple Threat Notification as a presumed-infection incident, not a maybe. Preserve the device rather than reflexively wiping it, because the forensic artefacts are what let a lab confirm the spyware family and the exploit path. Get the person to Access Now’s Digital Security Helpline, which supports human-rights defenders, journalists, and dissidents, and turn on Lockdown Mode on their Apple devices while analysis is pending. None of this is exotic, and most of it is free.
There is a reason the guidance leans so hard on preservation. Wiping a compromised phone destroys exactly the evidence that lets investigators attribute a campaign, warn other targets, and pressure vendors and governments. An activist’s instinct to factory-reset a “hacked” device is understandable and, in this narrow case, counterproductive. The better move is to switch to a known-clean device for sensitive communication, keep the suspect device powered and preserved, and let a trusted lab decide what it can recover. Collective defense also matters here: Citizen Lab recommends that anyone who receives a notification tell close contacts and collaborators to seek screening too, since spyware operators map networks, not just individuals.
My read: this is less a new revelation than a familiar one landing again. Mercenary spyware keeps ending up on the phones of students and opposition figures, the attribution keeps pointing at the state that bought it, and the vendor keeps issuing the same statement. What has genuinely changed is the defense side: Lockdown Mode, fast patching, Apple threat notifications, and free forensic tooling like MVT now form a real, repeatable playbook. The gap is not knowledge, it is adoption. The at-risk organizations that most need these controls are often the least resourced to run them, and that, more than any single zero-day, is the problem worth solving.
Primary Documents
- Citizen Lab, “Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist” (September 2, 2026)
- SHARE Foundation, report on students and opposition politicians targeted by spyware
- CyberScoop, “Pegasus, NoviSpy variant spyware found on devices of Serbian activists” (Tim Starks)
- Access Now, FAQ on Apple Threat Notifications and mercenary spyware