Politics
The SHARE Foundation, Citizen Lab, and Amnesty International documented 14 Serbian students and opposition figures infected with Pegasus and NoviSpy spyware ahead of elections. Zero-click exploits require no action from the target.
NewsOnScale Staff
September 9, 2026
A student activist in Serbia received a warning from Apple on their iPhone. Apple issues these warnings when it detects with high confidence that a device has been targeted by mercenary spyware. The student contacted the SHARE Foundation, a Belgrade-based digital rights organization.
Forensic analysis confirmed the device had been infected with Pegasus — military-grade spyware developed by Israeli company NSO Group and sold exclusively to governments and state agencies.
The infection happened through a zero-click exploit targeting Apple's iMessage application. Zero-click means exactly what it sounds like. The device was infected remotely. The student never clicked a link, never opened a file, never took any action. The phone was compromised without their knowledge or interaction.
What Was Found
The SHARE Foundation, working with the Citizen Lab at the University of Toronto and Amnesty International's Security Lab, documented at least 14 people in Serbia targeted with advanced spyware since early 2026. The organization described it as the largest documented wave of such surveillance in Serbia's history.
Those targeted include members of Serbia's student protest movement, civil society activists, an opposition member of parliament, and a local government official.
The Citizen Lab confirmed the Pegasus infection of the student activist with high probability. Amnesty International's Security Lab independently confirmed two additional devices infected with a new version of NoviSpy — Android spyware first discovered in Serbia in 2024, now rebuilt with specific measures designed to avoid detection by security experts.
In one case the spyware was found on the phone of a student whose device had previously been confiscated during police questioning. In another case private Viber messages from an infected phone were later broadcast on a pro-government Serbian television network.
The Timing
The surveillance campaign coincided with Serbia's local elections held on March 29, 2026. It stretches toward planned early parliamentary elections in October 2026, following months of student-led anti-government and anti-corruption protests that began after a train station roof collapse in Novi Sad killed 15 people in November 2024.
The Citizen Lab traced the Pegasus infection to a period across December 2025 through January 2026 — the months leading up to the March elections.
What Pegasus Actually Does
Pegasus is not ordinary spyware. It is military-grade surveillance technology. Once installed on a device it can access messages, emails, photos, contacts, and microphone and camera functions. It can track location in real time. It operates invisibly. The target has no indication the device is compromised.
NSO Group sells Pegasus exclusively to governments. It is not available to private individuals or corporations. When Pegasus appears on a device it means a government authorized and funded the infection.
The zero-click iMessage exploit used against the Serbian student has been patched by Apple in iOS 18.4.1, released in April 2025. Devices running software older than that version remain vulnerable to the same attack method.
Why This Matters Beyond Serbia
Serbia is a European country. It is a candidate for European Union membership. Its government is using military-grade spyware to surveil students and opposition politicians ahead of elections, with private communications later broadcast on state-aligned television.
This is not a distant authoritarian state. This is happening in a country with EU aspirations, in 2026, documented by three independent forensic organizations including the University of Toronto and Amnesty International.
The tools exist. The capability exists. Governments that want to surveil their citizens — including political opponents, journalists, and activists — have access to technology that leaves no trace, requires no physical access, and can be deployed remotely against anyone.
The Fourth Amendment to the United States Constitution protects Americans against unreasonable searches and seizures. The Supreme Court in Kyllo v. United States, 533 U.S. 27 (2001) held that warrantless surveillance of a home using technology not available to the general public constitutes an unconstitutional search.
The question of whether Americans are protected from Pegasus-class surveillance tools deployed without a warrant has not been answered definitively by any court. The technology has outpaced the legal framework designed to restrain it.
What Can Be Done
Apple's threat notification system is among the most important privacy protections available to ordinary users. Keeping devices updated is not optional security hygiene. For activists, journalists, candidates for office, and anyone whose communications might be of interest to a government actor, it is the most basic available defense.
The broader policy question — whether governments should be able to purchase and deploy military-grade spyware against their own citizens — is a question that elections are supposed to answer.
In Serbia it is being answered by the surveillance campaign itself.
DISCLOSURE: NewsOnScale is an independent media publication operated by AMILLI AI, CORP. JJ Johnson is the founder of AMILLI AI, CORP and a declared candidate for President of the United States in 2028. The facts in this article are drawn from published reports by the SHARE Foundation, the Citizen Lab at the University of Toronto, Amnesty International's Security Lab, CyberScoop, The Hacker News, and Security Affairs.