Executive Summary
In early 2026, researchers discovered the first confirmed Pegasus spyware infection of the year alongside NoviSpy variant infections targeting 14 Serbian individuals, including student activists, a parliament member, and local government official. The SHARE Foundation documented this as the largest wave of surveillance in Serbia to date, coinciding with local elections and student protests following the 2024 Novi Sad railway station collapse. Pegasus infections utilized zero-click exploits from December 2025 to January 2026, while NoviSpy variants were deployed during police detention and questioning of activists.
This incident highlights the continued weaponization of commercial spyware against civil society and democratic movements, demonstrating how state-sponsored surveillance capabilities are increasingly deployed to suppress political dissent and monitor opposition activities during critical electoral periods.
Why This Matters Now
State-sponsored spyware attacks against civil society are escalating globally, with commercial surveillance tools like Pegasus and NoviSpy being weaponized to suppress democratic movements and political opposition during critical electoral periods.
Attack Path Analysis
State-sponsored actors targeted Serbian activists through zero-click mobile exploits via Pegasus spyware and NoviSpy variants, compromising devices during police detention and remotely via Apple iOS vulnerabilities. Attackers gained privileged access to device functions, maintained persistent command channels, extracted sensitive communications and personal data, ultimately achieving surveillance objectives and political intimidation of democracy advocates.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Zero-click Pegasus exploit targeted iOS devices remotely without user interaction, while NoviSpy variants were installed during police detention when activists' phones were confiscated
MITRE ATT&CK® Techniques
Drive-by Compromise
Phishing: Spearphishing Link
Process Injection
Software Discovery: Security Software Discovery
Audio Capture
Screen Capture
Exfiltration Over C2 Channel
Indicator Removal on Host: File Deletion
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
GDPR – Security of Processing
Control ID: Article 32
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
CISA ZTMM 2.0 – Device Identity and Security
Control ID: Device Security
NYDFS 23 NYCRR 500 – Training and Monitoring
Control ID: 500.14
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
DORA – ICT Risk Management Framework
Control ID: Article 11
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
State-sponsored surveillance targeting activists creates critical risks for government communications, requiring enhanced egress security and zero trust segmentation against advanced persistent threats.
Higher Education/Acadamia
Student activist targeting via Pegasus and NoviSpy variants exposes university networks to lateral movement risks, demanding multicloud visibility and threat detection capabilities.
Civic/Social Organization
Spyware infections during political protests demonstrate urgent need for encrypted traffic protection and anomaly detection to safeguard civil society communications and operations.
Political Organization
Parliamentary member targeting during election periods highlights vulnerability to zero-click exploits, requiring comprehensive endpoint protection and secure hybrid connectivity solutions.
Sources
- Pegasus, NoviSpy variant spyware found on devices of Serbian activistshttps://cyberscoop.com/pegasus-novispy-variant-spyware-found-on-devices-of-serbian-activists/Verified
- SHARE Foundation Surveillance Report on Serbian Activistshttps://www.sharefoundation.info/Verified
- Citizen Lab Pegasus Project Researchhttps://citizenlab.ca/category/research/pegasus/Verified
- Amnesty International Security Lab NoviSpy Analysishttps://www.amnesty.org/en/latest/research/2024/06/novispay-spyware-serbia/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely limit the scope and reach of this mobile spyware campaign by constraining lateral movement between compromised devices and cloud infrastructure, reducing attacker access to connected services and communications platforms.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-based services and infrastructure connected to compromised mobile devices would likely experience restricted access paths, limiting the spyware's ability to reach broader organizational cloud resources and reducing initial attack surface expansion.
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation would likely constrain the compromised devices' access to cloud workloads and services, preventing elevated privileges on mobile endpoints from translating into broad cloud infrastructure access and reducing privilege escalation scope.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely restrict lateral movement between cloud services accessed from compromised devices, limiting the spyware's ability to pivot across connected communication platforms and reducing the blast radius of network compromise.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility would likely detect and constrain command and control communications flowing through cloud infrastructure, reducing the spyware's ability to maintain persistent channels and limiting command server reachability across distributed cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely limit data exfiltration pathways from cloud-connected services, constraining the volume and types of sensitive information the spyware could extract and reducing unauthorized outbound data flows to external destinations.
While activists would still face surveillance risks from compromised mobile devices, the scope of exposed cloud-based communications and organizational data would likely be significantly reduced, limiting the breadth of intelligence available for political intimidation campaigns.
Impact at a Glance
Affected Business Functions
- Political Advocacy Operations
- Civil Society Communications
- Parliamentary Activities
- Student Movement Coordination
Estimated downtime: N/A
Estimated loss: N/A
Complete device access including private communications, location data, audio recordings, screen captures, and sensitive political organizing information for 14 individuals including student activists, a parliament member, and local government official. Spyware provided full surveillance capabilities over extended periods from December 2025 to January 2026.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement from compromised mobile devices to cloud resources and internal networks
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration from infected endpoints to external command servers
- • Enable Encrypted Traffic controls with HPE to protect sensitive communications from interception during transit between activist devices and secure platforms
- • Establish Multicloud Visibility & Control to monitor for anomalous mobile-to-cloud authentication patterns and suspicious data access behaviors
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal mobile device communication patterns and alert on indicators of spyware C2 activity



