CITIZEN Lab and the SHARE Foundation confirmed a Pegasus spyware infection on the iPhone of a Serbian student activist, detected following an Apple Threat Notification in early September 2026. The interview and forensic work indicate the Pegasus deployment used a zero-click iMessage exploit, requiring no user interaction and potentially leaving the infection invisible to the target. Apple is believed to have patched the underlying iOS flaw with iOS 18.4.1, released in April 2025.
Forensic indicators point to infection activity in December 2025 and January 2026, and the case is described as part of Serbia’s largest documented spyware wave, with at least 14 targeted individuals ahead of the 2026 elections. While the victim preferred anonymity, researchers emphasised that Pegasus gives an attacker “full device access” and can covertly activate the microphone and camera, read notes and photos, and access encrypted messages.
In addition to Pegasus, the investigation notes a second spyware strand in the same wave: a NoviSpy Android variant that requires physical access to install. Amnesty International’s Security Lab described the NoviSpy build as newly developed to evade detection, with one case involving police confiscation of a phone. Attribution remains unconfirmed for who ordered or operated the Serbia 2026 Pegasus infection, though Pegasus is known to be NSO Group’s state‑client product.
The report underlines the broad risk to activists, students, and political figures, and it calls for rapid response: treating Apple Threat Notifications seriously, updating devices, and enabling protective measures such as Lockdown Mode on iOS and Advanced Protection on Android.