BELGRADE — Serbia is facing a growing digital surveillance controversy after at least 14 members of civil society, including student activists and opposition figures, were targeted with sophisticated spyware, according to digital rights investigators.
The SHARE Foundation said the cases represent the largest documented wave of advanced spyware targeting in Serbia to date. The revelations have intensified concerns about digital surveillance and political freedoms as the country moves toward another potentially contentious election period.
The investigation became public in August after Apple sent threat notifications to people in Serbia warning that they may have been targeted by mercenary spyware. Twelve recipients subsequently contacted SHARE Foundation for forensic examination, while investigators identified two additional infections.
Among those targeted were members of Serbia’s student protest movement, activists, an opposition member of parliament and a local opposition councilor. The targeting period coincided with Serbia’s March 29 local elections, according to SHARE Foundation.
Pegasus discovered on student activist’s iPhone
The most significant finding came from the University of Toronto’s Citizen Lab, which confirmed that an iPhone belonging to a member of Serbia’s student movement had been infected with Pegasus, the powerful spyware developed by Israeli company NSO Group.
Investigators determined that the infection used a so-called zero-click exploit targeting Apple’s iMessage system. Unlike conventional phishing attacks, a zero-click attack does not require the victim to open a malicious link or interact with a suspicious message.
Citizen Lab found high-confidence evidence indicating the Pegasus infection occurred sometime between December 2025 and January 2026. The researchers said Pegasus can provide an attacker with extensive access to a compromised device, including private information, while also potentially allowing the microphone and camera to be activated covertly.
The vulnerability used in that particular attack has since been addressed by Apple through security updates, according to Citizen Lab.
NoviSpy adds another layer to the investigation
The investigation also uncovered a newer version of NoviSpy, an Android spyware previously exposed by Amnesty International in connection with Serbia.
SHARE Foundation said one of the newly identified NoviSpy infections involved a student movement member whose phone had previously been confiscated during police questioning. Amnesty International’s Security Lab independently examined the findings and confirmed the infection.
NoviSpy is capable of extracting sensitive information from phones and can potentially activate a device’s microphone or camera. Earlier Amnesty investigations found evidence that Serbian authorities had used Cellebrite mobile-forensics technology in cases involving the installation of NoviSpy on phones belonging to activists and journalists.
That earlier history is now drawing renewed attention because Cellebrite previously suspended Serbian police access to its technology following allegations concerning misuse of its tools, according to reporting by TechCrunch.
Government denies spying allegations
Serbian officials have rejected claims that state authorities were responsible for spying on students.
Serbian Parliament Speaker Ana Brnabić said she had no information indicating that the government had targeted the students and dismissed the allegations.
That denial is significant because the technical evidence establishes that devices were targeted or infected, but it does not by itself publicly establish which individual, organization or government agency ordered every operation.
The SHARE Foundation, however, has warned that the pattern is particularly troubling because many of those targeted were involved in Serbia’s student-led protest movement or opposition politics.
Why the timing matters
The spyware revelations come against the backdrop of Serbia’s prolonged political tensions.
Student-led protests erupted after the November 2024 collapse of a railway-station canopy in Novi Sad killed 16 people. The demonstrations evolved into a broader movement demanding accountability and challenging President Aleksandar Vučić’s government.
The March 2026 local elections became an important test of the opposition movement’s ability to organize politically. With further national political developments looming, digital-rights groups warn that sophisticated surveillance could have consequences beyond individual privacy.
Citizen Lab researcher John Scott-Railton said the findings and Apple’s warnings point to aggressive targeting of Serbia’s pro-democracy movement ahead of key election cycles.
A warning beyond Serbia
The controversy also highlights the growing global concern surrounding commercial spyware.
Apple said it sent threat notifications on August 13 to targeted users in 110 countries and has issued such warnings to users in more than 150 countries overall.
Pegasus has become one of the world’s most controversial surveillance tools because of its ability to penetrate smartphones and collect highly sensitive information. NSO Group was placed on the U.S. government’s blacklist in 2021 amid concerns about the misuse of its technology.
For Serbia, however, the immediate question is more politically explosive: why were students, activists and opposition figures among those targeted, and who authorized the surveillance?
The technical investigation has answered part of the mystery by confirming sophisticated spyware on at least some devices.
The question of who was ultimately behind the campaign remains unresolved.
WWC ONE MEDIA MJE

Leave a Reply