A report found that spyware targeted the phones of organizers of anti-government protests in central Belgrade, demonstrations that denounced corruption. The available reporting does not identify the specific malware, intrusion vector, perpetrators, number of victims, or the operational impact of the compromises.
Related reporting in Serbia alleged that students and opposition figures were monitored with Pegasus ahead of elections. US Congressman Joe Wilson separately accused President Aleksandar Vučić’s government of surveilling Serbian citizens; neither allegation is independently substantiated in the available material.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
In August 2026, 12 people contacted SHARE Foundation's digital-forensics team after receiving Apple Threat Notifications. Eleven of the 12 devices were presumed infected pending further forensic confirmation.
Serbian demonstrators held an anti-government protest in central Belgrade denouncing corruption.
SHARE Foundation identified a newly built Android spyware family resembling NoviSpy on two Serbian student-movement members' devices. One device was reportedly infected after confiscation during police questioning, while private Viber messages from the other device were later displayed on Informer TV.
Citizen Lab and the SHARE Foundation found high-confidence indicators that an iPhone used by a Serbian student protest-movement member was infected with NSO Group's Pegasus via an iMessage zero-click exploit. The indicators span December 2025 through January 2026; SHARE also reported at least 14 advanced-spyware targets in Serbia since the start of 2026.
Apple released iOS 18.4.1 in April 2025. Citizen Lab later assessed that this release had patched the iMessage zero-click exploit used in the Pegasus infection of a Serbian student activist.
Two journalists from the Balkan Investigative Reporting Network were targeted with NSO Group's Pegasus spyware in Serbia.
Twenty-nine Members of the European Parliament asked the EU to slow Serbia's accession process pending an investigation into alleged government spyware use. They cited findings involving Pegasus and NoviSpy targeting and urged that further accession progress be conditioned on rule-of-law accountability.
Serbia's BIA intelligence agency denied allegations that Serbian authorities targeted activists and opposition figures with Pegasus and NoviSpy, characterizing the claims as sensationalism motivated by foreign intelligence services and pressure groups.
SHARE Foundation reported that students and opposition politicians in Serbia were targeted by spyware, expanding the reported targets beyond student activists and protest organizers.
A report said spyware targeted the phones of Serbian protest organizers. The available information did not identify the spyware, its operator, the responsible party, affected individuals, intrusion method, or scope of impact.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
16 references tracked. Mallory keeps watching after this page renders.
cyberscoop.com
Open sourcereddit.com
Open sourceinfosec.pub
Open sourcecyberveille.ch
Open sourcecitizenlab.ca
Open sourcebloomberg.com
Open sourcesharefoundation.info
Open sourcesupport.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.