FT reports spyware targeting in Serbia: Students’ and activists’ devices infected with Pegasus and NoviSpy
Translated from Serbian and summarized by DistantNews. Read the original for the full story.
At a glance
- More than 10 Serbian students and opposition members were reportedly targeted by spyware this year, in what was described as the country’s largest documented surveillance wave.
- One student activist’s phone was infected remotely with Pegasus, while NoviSpy was allegedly installed on another person’s device during police detention.
- The SHARE Foundation documented 14 cases, while Citizen Lab said at least one Pegasus infection used a zero-click vulnerability in Apple’s iMessage.
More than 10 students and opposition figures in Serbia have been targeted by spyware since the start of the year, according to reporting by the Financial Times. The cases represent the largest documented wave of such surveillance identified in the country.
Canadian digital-security experts confirmed at least one case in which a student activist’s phone was infected remotely with Pegasus, spyware developed by Israeli company NSO Group. In another case, domestically developed surveillance software known as NoviSpy was allegedly installed on a person’s device while that person was in police custody.
The findings emerged as President Aleksandar Vučić prepared for parliamentary elections in October. A strong student protest movement is expected to pose the ruling party’s biggest challenge. Journalists, activists and civil-society members have previously been targeted by surveillance technologies, but the new cases appear to mark the broadest identified use of spyware in Serbia.
The Serbian human-rights organization SHARE Foundation documented 14 cases this year. Twelve targets contacted the group after Apple warned in August that their iPhones might have been compromised. Citizen Lab in Toronto analyzed one case and said Pegasus entered the device through a zero-click flaw in Apple’s iMessage, meaning the target did not need to click a link or take any other action. Citizen Lab said Apple likely fixed the vulnerability through later software updates.
The remaining 11 cases are still under analysis. Once installed, Pegasus can bypass most encryption on modern smartphones and transmit copies of their contents, including messages from applications such as Signal and WhatsApp. John Scott-Railton of Citizen Lab said, “This new wave of Apple threat notifications shows that Serbia’s peaceful pro-democracy movement is being aggressively targeted by commercial spyware ahead of the key 2026 election cycles.”
This new wave of Apple threat notifications shows that Serbia’s peaceful pro-democracy movement is being aggressively targeted by commercial spyware ahead of the key 2026 election cycles.
Originally published by N1 Serbia in Serbian. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.