VYPR
researchPublished Sep 2, 2026· 1 source

Pegasus and NoviSpy Variants Target Serbian Activists in Major Surveillance Wave

Researchers confirm Pegasus and a new NoviSpy variant spyware infections targeting Serbian student activists, marking the largest documented surveillance wave in the country.

Researchers have confirmed the first documented Pegasus spyware infection of 2026, alongside infections from a new variant of NoviSpy, targeting Serbian student activists and other individuals. The SHARE Foundation reported that 14 people were targeted in this wave, including a member of parliament and a local government official. These findings were corroborated by Amnesty International and the University of Toronto's Citizen Lab, who confirmed the infections and suggested that Serbian authorities are likely responsible for this extensive surveillance operation.

The SHARE Foundation noted that the timing of these infections coincided with the lead-up to crucial local elections in March, which were seen as a significant test for the ruling Serbian Progressive Party. Student protests had been escalating following a railway station canopy collapse in Novi Sad in 2024 and in anticipation of upcoming parliamentary elections in October. While Serbian activists have been targeted with spyware, including Pegasus and NoviSpy, in the past, the SHARE Foundation described this as the most significant wave of such surveillance in the country to date.

Spyware is notorious for its ability to gain complete access to a device, enabling attackers to record screens, capture audio through microphones, and exfiltrate sensitive data. In the case of the NoviSpy variant, the SHARE Foundation indicated that one infection occurred after authorities confiscated a student's phone during police questioning. Another device was found to be infected with the same spyware after private messages were leaked by a media outlet aligned with the ruling party.

Evidence gathered by the SHARE Foundation and supported by Amnesty International points towards Serbian police or secret service agencies as the perpetrators behind the NoviSpy variant infections. "These new forensic findings show that Serbian student activists continue to be targeted with invasive spyware," stated Donncha Ó Cearbhaill, head of Amnesty International’s Security Lab. "As with NoviSpy, which Amnesty International found used extensively in Serbia in 2024, the evidence suggests the infections are being carried out during detention by the Serbian authorities."

The Pegasus spyware infection, attributed to NSO Group, was confirmed on a student activist's device with "high probability" via a zero-click exploit. This type of exploit is particularly concerning as it requires no user interaction to compromise a device. Citizen Lab researchers noted that this case echoes the initial discovery of Pegasus a decade ago, which was also used against a pro-democracy activist. "Today, Pegasus is still being used to hack people campaigning for democracy," said John Scott-Railton, a senior researcher at Citizen Lab. "NSO spent a decade promising reform, yet their spyware is still an instrument of political repression."

NSO Group maintains that its spyware is intended for use against terrorism and serious crime, and that it actively works to halt any discovered abuses. The discoveries in Serbia were prompted by threat notifications sent to the targeted individuals by Apple. Bill Marczak, a senior researcher at Citizen Lab, advised users to ensure their devices are updated to the latest iOS version, as Apple's updates have reportedly disrupted the specific exploit used in this instance.

Synthesized by Vypr AI