Actor Profile

NSO Group is an Israeli cyber intelligence company that develops and sells Pegasus spyware to government clients. The company markets its surveillance technology as a tool for law enforcement and intelligence agencies to combat terrorism and crime. NSO Group has been linked to numerous cases of spyware abuse targeting journalists, activists, opposition politicians, and civil society members globally. The actor operates as a commercial surveillance vendor, providing mercenary spyware capabilities to state actors who deploy the tools against targets of interest.

TTPs (Tactics, Techniques, Procedures)

The attack employed a zero-click iMessage exploit to deliver Pegasus spyware without user interaction (T1659 - Content Injection). The exploit targeted Apple iMessage and was patched in iOS 18.4.1 (April 2025). Infection indicators were observed from December 2025 through January 2026. The campaign demonstrates sophisticated initial access capabilities requiring no victim interaction (T1566 - Phishing alternative via zero-click). Pegasus provides comprehensive mobile device surveillance capabilities including data exfiltration (T1041), location tracking, communications interception, and credential access (T1555 - Credentials from Password Stores). The targeting coincided with Serbian local elections (March 29, 2026), suggesting intelligence collection motivated by political surveillance objectives.

Targets & Patterns

At least 14 individuals in Serbia were targeted with advanced spyware since early 2026, including student protest movement members, activists, a member of parliament, and an opposition party local councilor. The targeting pattern focused on political opposition figures and civil society activists during a sensitive political period surrounding local elections. The victims represent individuals engaged in protest activities and political opposition to the Serbian government. A separate but related campaign deployed NoviSpy Android spyware against another student activist whose device was confiscated during police detention, indicating physical access operations complementing remote exploitation. The timing and victim selection suggest state-sponsored surveillance aimed at monitoring and potentially suppressing political dissent and opposition activities.

Historical Context

This incident continues a documented pattern of surveillance technology abuse in Serbia. Previous cases include the use of Cellebrite forensic tools to deploy NoviSpy spyware on Android devices. The 2026 campaign represents an escalation with the deployment of NSO Group's Pegasus alongside continued use of Android spyware variants. SHARE Foundation detected a new Android spyware strain similar to NoviSpy but specifically engineered to evade detection by security researchers. Evidence of spyware deployment includes private Viber messages from a compromised device being disclosed on Informer TV, a pro-government Serbian media outlet. The campaign aligns with global patterns of Pegasus abuse documented by Citizen Lab and other research organizations, where the spyware has been deployed against civil society targets in numerous countries. Apple issued threat notifications to users in 110 countries regarding suspected mercenary spyware attacks during this timeframe.

Defensive Recommendations

  • Update iOS devices immediately to version 18.4.1 or later to patch the iMessage zero-click vulnerability exploited in this campaign
  • Enable iOS Lockdown Mode for high-risk users including activists, journalists, and political opposition members to restrict attack surface for zero-click exploits
  • Conduct regular mobile device forensic analysis using tools like MVT (Mobile Verification Toolkit) to detect Pegasus infection indicators on iOS devices
  • Implement organizational policies requiring Android users at risk to enroll in Google's Advanced Protection Program for enhanced security against targeted attacks
  • Enable WhatsApp Strict Account Settings to automatically apply most restrictive configurations and block media from unknown contacts, mitigating spyware delivery vectors
  • Monitor for Apple threat notifications and treat mercenary spyware alerts as high-priority incidents requiring immediate device forensics and potential replacement

---

# Geopolitical Context

Geopolitical Context

The deployment of NSO Group's Pegasus spyware against Serbian student protesters and opposition figures represents a pattern of surveillance consistent with authoritarian governance tactics in the Western Balkans. The timing—coinciding with local elections in March 2026—suggests the use of commercial spyware as a tool for political control and opposition monitoring. At least 14 individuals, including student activists, opposition parliamentarians, and local councilors, were targeted during a politically sensitive period. The case is notable for combining Israeli-origin zero-click exploits with locally deployed Android malware (NoviSpy and a newly identified variant), the latter installed during police detention. The disclosure of private Viber messages on pro-government television indicates operational coordination between surveillance capabilities and state-aligned media. This incident fits within broader concerns about democratic backsliding in Serbia and the proliferation of offensive cyber tools to semi-authoritarian regimes in Europe's periphery.

State Actor Alignment

NSO Group's Pegasus is an Israeli-origin commercial surveillance tool sold exclusively to government clients under export controls. While Citizen Lab and SHARE Foundation have not formally attributed the operation to Serbian state actors, the targeting pattern—opposition figures during an election cycle—and the installation of Android spyware during police custody strongly suggest state involvement or authorization. Serbia is not publicly listed as an NSO client, though the company's customer base has historically included governments with poor human rights records. The use of Cellebrite forensic tools (an Israeli company) to deploy NoviSpy in prior incidents indicates Serbian law enforcement access to multiple commercial surveillance platforms. The European Union has expressed concern over rule-of-law issues in Serbia, an EU candidate country, though no sanctions related to spyware abuse have been imposed. Apple's threat notifications to users in 110 countries reflect the global scope of mercenary spyware deployment.

Business Impacty pro region

This case underscores the normalization of offensive cyber capabilities in the Western Balkans, a region where EU accession processes have not prevented the acquisition and deployment of sophisticated surveillance tools against civil society. For the European Union, the incident complicates Serbia's accession trajectory and raises questions about the adequacy of export controls on dual-use technologies originating from member states and partners like Israel. The targeting of student movements—a key driver of political change in the region historically—may embolden similar tactics in neighboring states with fragile democratic institutions. The disclosure also highlights the role of civil society organizations (Citizen Lab, SHARE Foundation, Amnesty International's Security Lab) in documenting abuses where formal accountability mechanisms are weak. For technology vendors, the case adds to reputational and legal pressure on NSO Group and the broader mercenary spyware industry, particularly following increased scrutiny from the United States and European Parliament. The coordination between surveillance operations and pro-government media amplifies the chilling effect on dissent.

Forecast

If international pressure on NSO Group and similar vendors intensifies, Serbia may increasingly rely on domestically developed or regionally sourced spyware variants, as evidenced by the evolution of NoviSpy. Should the EU prioritize rule-of-law conditionality in accession negotiations, Serbian authorities may face constraints on overt surveillance abuses, though enforcement mechanisms remain limited. If student and opposition movements sustain momentum, further targeting is likely, particularly around future electoral cycles. The disclosure of this incident may prompt Apple and Google to enhance protections for high-risk users, though zero-click exploits will remain attractive to state actors. If civil society documentation continues, additional cases in Serbia and neighboring states are likely to surface, potentially triggering targeted sanctions or export control reforms within the EU framework. The interplay between commercial spyware proliferation and democratic erosion in EU candidate countries will likely remain a contentious policy issue through 2026–2027.