DistantNews
Support us

Citizen Lab researcher: We are very confident Serbian students faced a spyware attack

From N1 Serbia · () Serbian

Translated from Serbian and summarized by DistantNews. Read the original for the full story.

At a glance

Interview Named sources Under investigation
  • Citizen Lab researcher John Scott-Railton said the organization was very confident that Pegasus spyware had targeted students’ phones in Serbia.
  • He said investigators found high-confidence indicators consistent with a zero-click infection through iMessage, which would not alert the user.
  • Scott-Railton said forensic analysis can identify an infection, but determining who ordered an attack requires evidence from Pegasus users’ servers, and the investigation continues.

Citizen Lab is “very confident” that Pegasus spyware was used in an attack on students’ phones in Serbia, researcher John Scott-Railton told Serbian outlet Insajder.

The investigation began with forensic traces collected from devices. Researchers examined logs, files and other artifacts that can remain after a vulnerability is exploited and a phone becomes infected. They searched for general signs of intrusion and hacking, as well as indicators associated with particular spyware families.

We found high-confidence indicators pointing to NSO Group’s Pegasus spyware, which we have tracked for more than 10 years, since our first discovery of Pegasus in August 2016.

· John Scott-RailtonHe described the forensic findings from phones examined by Citizen Lab.

“We found high-confidence indicators pointing to NSO Group’s Pegasus spyware, which we have tracked for more than 10 years, since our first discovery of Pegasus in August 2016,” Scott-Railton said. The indicators matched a zero-click infection through iMessage, meaning users would not have needed to interact with anything and would not have seen warning signs on their devices.

There is no substitute for expert forensic analysis.

· John Scott-RailtonHe said ordinary users cannot reliably determine whether Pegasus infected their phones.

Student Jelena Kontić, speaking at the Students in Blockade conference, said she was the “first victim of Pegasus in 2026.” She said the possible reason for targeting her was her active involvement in the movement’s field campaign, “Student in Every Village.”

Scott-Railton said ordinary phone users cannot reliably determine whether commercial spyware such as Pegasus infected their devices. “There is no substitute for expert forensic analysis,” he said. He compared security warnings to ants in a kitchen: “If you see one, many more are hiding.” Identifying who commissioned an attack and where stolen data was sent, he said, would require reliable evidence from the servers of the government agency or other Pegasus user. Citizen Lab’s forensic investigation remains under way.

If you see one, many more are hiding.

· John Scott-RailtonHe compared security warnings to ants in a kitchen and urged further checks for spyware infections.
About this summary

Originally published by N1 Serbia in Serbian. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.