Executive Summary

In early 2026, researchers discovered the first confirmed Pegasus spyware infection of the year alongside NoviSpy variant infections targeting 14 Serbian individuals, including student activists, a parliament member, and local government official. The SHARE Foundation documented this as the largest wave of surveillance in Serbia to date, coinciding with local elections and student protests following the 2024 Novi Sad railway station collapse. Pegasus infections utilized zero-click exploits from December 2025 to January 2026, while NoviSpy variants were deployed during police detention and questioning of activists.

This incident highlights the continued weaponization of commercial spyware against civil society and democratic movements, demonstrating how state-sponsored surveillance capabilities are increasingly deployed to suppress political dissent and monitor opposition activities during critical electoral periods.

Why This Matters Now

State-sponsored spyware attacks against civil society are escalating globally, with commercial surveillance tools like Pegasus and NoviSpy being weaponized to suppress democratic movements and political opposition during critical electoral periods.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Pegasus infections occurred through zero-click exploits requiring no victim interaction, while NoviSpy variants were installed during police detention when authorities physically accessed activists' devices.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely limit the scope and reach of this mobile spyware campaign by constraining lateral movement between compromised devices and cloud infrastructure, reducing attacker access to connected services and communications platforms.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud-based services and infrastructure connected to compromised mobile devices would likely experience restricted access paths, limiting the spyware's ability to reach broader organizational cloud resources and reducing initial attack surface expansion.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust segmentation would likely constrain the compromised devices' access to cloud workloads and services, preventing elevated privileges on mobile endpoints from translating into broad cloud infrastructure access and reducing privilege escalation scope.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely restrict lateral movement between cloud services accessed from compromised devices, limiting the spyware's ability to pivot across connected communication platforms and reducing the blast radius of network compromise.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility would likely detect and constrain command and control communications flowing through cloud infrastructure, reducing the spyware's ability to maintain persistent channels and limiting command server reachability across distributed cloud environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress controls would likely limit data exfiltration pathways from cloud-connected services, constraining the volume and types of sensitive information the spyware could extract and reducing unauthorized outbound data flows to external destinations.

Impact (Mitigations)

While activists would still face surveillance risks from compromised mobile devices, the scope of exposed cloud-based communications and organizational data would likely be significantly reduced, limiting the breadth of intelligence available for political intimidation campaigns.

Impact at a Glance

Affected Business Functions

  • Political Advocacy Operations
  • Civil Society Communications
  • Parliamentary Activities
  • Student Movement Coordination
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Complete device access including private communications, location data, audio recordings, screen captures, and sensitive political organizing information for 14 individuals including student activists, a parliament member, and local government official. Spyware provided full surveillance capabilities over extended periods from December 2025 to January 2026.

Recommended Actions

  • Implement Zero Trust Segmentation to prevent lateral movement from compromised mobile devices to cloud resources and internal networks
  • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration from infected endpoints to external command servers
  • Enable Encrypted Traffic controls with HPE to protect sensitive communications from interception during transit between activist devices and secure platforms
  • Establish Multicloud Visibility & Control to monitor for anomalous mobile-to-cloud authentication patterns and suspicious data access behaviors
  • Activate Threat Detection & Anomaly Response capabilities to baseline normal mobile device communication patterns and alert on indicators of spyware C2 activity

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image