Cyberscoop

Pegasus, NoviSpy variant spyware found on devices of Serbian activists


Researchers say they have uncovered the first confirmed Pegasus spyware infection of 2026, as well as another spyware variant infection, targeting Serbian student activists and others in what one group called the largest documented wave of that kind of surveillance in the country to date.

The SHARE Foundation said Wednesday that it found 14 people targeted in all, including one member of parliament and a local government official. The University of Toronto’s Citizen Lab confirmed the Pegasus infection of a student activist with “high probability,” while Amnesty International confirmed that two devices had been infected with a new version of the NoviSpy spyware.

The SHARE Foundation noted that the infections coincided with the build-up to key local elections in March that were viewed as a test of the ruling Serbian Progressive Party, with student protests rising in the wake of the 2024 Novi Sad railway station canopy collapse, and in advance of October parliamentary elections.

Serbian activists have found themselves targeted with spyware numerous times before, including by Pegasus and NoviSpy. But the SHARE Foundation said this was the biggest wave there so far.

Spyware is noted for its ability to access everything on a device, record screens or take over its microphone.

NoviSpy variant infections

One NoviSpy variant infection came after authorities took a student’s phone during police questioning, and the same spyware was found on another device as well after private messages from the phone were disclosed by a media outlet that favors the ruling party, SHARE Foundation said.

The SHARE Foundation said signs point to Serbian police or secret service being behind the NoviSpy variant cases, with Amnesty International offering a similar assessment. 

“These new forensic findings show that Serbian student activists continue to be targeted with invasive spyware,” Donncha Ó Cearbhaill, head of Amnesty International’s Security Lab, told CyberScoop. “As with NoviSpy, which Amnesty International found used extensively in Serbia in 2024, the evidence suggests the infections are being carried out during detention by the Serbian authorities.”

Pegasus infection

In the case of the infection from NSO Group’s Pegasus spyware, it’s rare for investigators to determine who specifically made use of it, although they found that the student’s device was hacked with a Pegasus zero-click exploit from December of last year to January of this year. The infection came via a zero-click exploit — meaning without victim interaction.

But Citizen Lab said the Serbian case harkens back to the first discovery of Pegasus a decade ago when it was against a pro-democracy activist, Ahmed Mansoor.

“Today, Pegasus is still being used to hack people campaigning for democracy,” said John Scott-Railton, senior researcher. “NSO spent a decade promising reform, yet their spyware is still an instrument of political repression.”

NSO Group maintains that its spyware is for usage against terrorism and crime, and that it halts any abuses it discovers.

The spyware discoveries in Serbia came after Apple sent threat notifications to the targets.

“Apple’s updates have broken this particular exploit, so we urge everyone to make sure they are updated to the latest version of iOS,” said Bill Marczak, senior researcher at Citizen Lab.

Written by Tim Starks

Tim Starks is senior reporter at CyberScoop. His previous stops include working at The Washington Post, POLITICO and Congressional Quarterly. An Evansville, Ind. native, he’s covered cybersecurity since 2003. Email Tim here: tim.starks@cyberscoop.com.



Source link