The Citizen Lab, working with Serbia’s SHARE Foundation, confirmed that a member of Serbia’s student pro-democracy movement was infected with NSO Group’s Pegasus spyware through a zero-click iMessage exploit, the first confirmed Pegasus case of 2026. The infection was detected after the target received an Apple Threat Notification, and forensic analysis found high-confidence indicators of compromise dating to December 2025 and January 2026. Separately, Amnesty International and the SHARE Foundation confirmed a new variant of NoviSpy, Android spyware previously linked to Serbian authorities’ use of Cellebrite forensic tools, on the device of another movement member.
The SHARE Foundation has now documented at least 14 people targeted in this wave, including a member of parliament and a local councilor, timed to Serbia’s 2026 election cycle. Citizen Lab wrote that “an iMessage zero-click exploit was used to infect the device with NSO Group’s Pegasus spyware,” and that the exploit “has subsequently been patched by Apple as of iOS 18.4.1.”
The original insight is the pairing, not either tool alone: Pegasus for zero-click remote infection and NoviSpy for physical-access infection via forensic extraction tools represent two different acquisition models converging on the same target set, which means device hygiene alone will not close the gap. An organization advising at-risk personnel, journalists, civil society staff, executives with cross-border exposure, needs a response plan that covers both the software update discipline that stops zero-click exploits and the operational discipline (device custody, lock screen policy) that stops physical-access tooling, because attackers are demonstrably using both against the same population.
Related: how another private surveillance vendor’s tooling reached state customers and why legal action against nation-state-linked operators rarely changes the underlying incentive.