NoviSpy is an Android spyware family first publicly identified in Serbia in 2024. It has been used against journalists, environmental and civil-society activists, and members of Serbia’s student movement. Forensic investigations found infections after targets’ phones were seized during police detentions, interviews, or questioning. The documented infection chain involved unlocking devices with Cellebrite mobile-forensic tooling and subsequently installing the spyware; exploitation of CVE-2024-43047 was also associated with privileged access to targeted Qualcomm-based Android devices.
NoviSpy collects sensitive data from compromised devices, including communications and other user data, captures screenshots, and can remotely activate the microphone and camera. Samples were configured to exfiltrate collected data to operator-controlled infrastructure. A newer variant identified in 2026 incorporated enhanced mechanisms intended to evade forensic detection. Technical and operational evidence has been assessed as linking NoviSpy to Serbia’s Security Information Agency (BIA), with high-confidence attribution reported by Amnesty International. Serbian authorities and BIA have denied allegations of unlawful spyware use.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Last November, the company addressed a second Android zero-day (CVE-2024-43047) used by the Serbian government in NoviSpy spyware attacks, which was first tagged as exploited by Google Project Zero in October.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Evidence from the NoviSpy infections pointed to Serbian government authorities.
NoviSpy (nouvelle variante) : implant Android identifié pour la première fois en Serbie en 2024 ; la nouvelle variante a été confirmée sur deux appareils supplémentaires par Amnesty Security Lab.
NoviSpy, a previously unknown Android spyware, provides Serbian authorities with extensive surveillance capabilities once installed on a target’s device. It was installed on devices while targets were detained or interviewed by Serbian police or the BIA.
Amnesty’s Security Lab, analyzed Milanov’s phone and indeed found that it had been unlocked using Cellebrite and had installed an Android spyware that Amnesty calls NoviSpy, from the Serbian word for “new.”
Amnesty’s Security Lab, analyzed Milanov’s phone and indeed found that it had been unlocked using Cellebrite and had installed an Android spyware that Amnesty calls NoviSpy, from the Serbian word for “new.”
Last November, the company addressed a second Android zero-day (CVE-2024-43047) used by the Serbian government in NoviSpy spyware attacks...
10 distinct techniques documented for this family, organized by ATT&CK tactic.
“Pegasus and NoviSpy spyware both have extraordinary snooping capabilities and can see photos, contacts, messages and files stored on phones.” A confirmed NoviSpy victim’s text messages were read live on a television network.
„истиот вид шпионски софтвер бил откриен и на втор уред, откако приватни Viber пораки од тој телефон биле јавно прикажани во живо на Informer TV“
Amnesty International was also able to recover and decrypt surveillance data captured by NoviSpy ... which included screenshots of email accounts, Signal and WhatsApp messages and social media activity.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Spyware identified on phones of Serbian student activists and other targets; the cited investigative groups assessed that evidence from these infections pointed to Serbian government authorities.
Implant Android de surveillance conçu pour contourner les méthodes de détection qui avaient exposé une version antérieure. Des infections auraient notamment eu lieu après la saisie de téléphones d’étudiants par la police.
Android spyware requiring physical device access for installation. The reported newer version uses enhanced evasion mechanisms to avoid detection; an earlier 2024 version was configured to exfiltrate data to an IP address belonging to Serbia's BIA.
Locally developed Android spyware used against Serbian activists; the reported variant was allegedly installed while the target was detained by Serbian authorities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.