NoviSpy is an Android spyware family used to surveil Serbian civil-society targets, including activists and journalists. Forensic investigations have linked its deployment with Serbian police and the Security Information Agency (BIA), with attribution to the BIA assessed at high confidence. The malware has been installed after authorities obtained physical custody of targets’ devices during arrests, detentions, police questioning, or interviews. Documented operations involved device unlocking and data extraction using Cellebrite forensic tools, followed by spyware installation; exploitation of CVE-2024-43047 was also associated with targeted NoviSpy activity against confiscated Android devices. NoviSpy can capture data from compromised devices and covertly activate the microphone and camera for remote surveillance. Evidence indicates the family had been in use for several years by 2024 and that infections extended beyond isolated cases, consistent with systematic targeting of Serbian civil society. Newer NoviSpy-like Android variants were identified targeting members of Serbia’s student protest movement in 2026 and included measures intended to hinder forensic detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Last November, the company addressed a second Android zero-day (CVE-2024-43047) used by the Serbian government in NoviSpy spyware attacks, which was first tagged as exploited by Google Project Zero in October.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Amnesty’s Security Lab, analyzed Milanov’s phone and indeed found that it had been unlocked using Cellebrite and had installed an Android spyware that Amnesty calls NoviSpy, from the Serbian word for “new.”
Amnesty’s Security Lab, analyzed Milanov’s phone and indeed found that it had been unlocked using Cellebrite and had installed an Android spyware that Amnesty calls NoviSpy, from the Serbian word for “new.”
Last November, the company addressed a second Android zero-day (CVE-2024-43047) used by the Serbian government in NoviSpy spyware attacks...
Last November, the company addressed a second Android zero-day (CVE-2024-43047) used by the Serbian government in NoviSpy spyware attacks...
10 distinct techniques documented for this family, organized by ATT&CK tactic.
“the same spyware was found on another device as well after private messages from the phone were disclosed by a media outlet that favors the ruling party.”
„истиот вид шпионски софтвер бил откриен и на втор уред, откако приватни Viber пораки од тој телефон биле јавно прикажани во живо на Informer TV“
Amnesty International was also able to recover and decrypt surveillance data captured by NoviSpy ... which included screenshots of email accounts, Signal and WhatsApp messages and social media activity.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware used against Serbian student-movement members; the report also describes a newly built, functionally similar Android spyware variant designed to evade security-expert detection.
Android spyware used against Serbian student movement members; the report states that Cellebrite forensic tools have been used to deploy it following device confiscation.
NoviSpy is Android spyware reportedly found on a Serbian student-movement member's device; the content also states that Cellebrite forensic tools had been used to plant it in previous cases.
Invasive spyware used extensively in Serbia, reportedly capable of broad device surveillance. The newly identified variant was found on devices belonging to Serbian student activists, with evidence suggesting infections were conducted during detention by Serbian authorities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.