Executive Summary
In December 2025 through January 2026, NSO Group's Pegasus spyware infected the iPhone of a Serbian student protest movement member using a zero-click iMessage exploit. The attack was part of a broader surveillance campaign targeting at least 14 Serbian activists, opposition politicians, and student leaders coinciding with March 2026 local elections. Citizen Lab and SHARE Foundation confirmed the infection, while a separate incident involved NoviSpy Android malware deployed during police detention of another student activist.
This incident highlights the escalating use of commercial spyware against civil society, particularly as authoritarian governments increasingly weaponize surveillance technology to suppress political dissent and monitor opposition movements ahead of critical elections.
Why This Matters Now
Commercial spyware attacks against civil society are surging globally, with governments deploying zero-click exploits to suppress political opposition. This Serbian case demonstrates how surveillance technology threatens democratic participation and requires immediate defensive measures.
Attack Path Analysis
NSO Group's Pegasus spyware infected a Serbian student activist's iPhone through a zero-click iMessage exploit during December 2025-January 2026. The attack leveraged iOS vulnerabilities to gain initial access, escalated to full device privileges, established persistent command and control channels, and continuously exfiltrated sensitive communications and data. The spyware operated covertly to monitor activist communications during a politically sensitive period coinciding with local elections.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Zero-click iMessage exploit delivered Pegasus spyware to target iPhone without user interaction, exploiting iOS vulnerabilities later patched in iOS 18.4.1
Related CVEs
CVE-2023-42824
CVSS 7.8A buffer overflow vulnerability in Apple iOS iMessage processing allows remote attackers to execute arbitrary code without user interaction via zero-click exploit.
Affected Products:
Apple iOS – < 18.4.1
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Content Injection
Execution Guardrails
Application Layer Protocol
Data from Local System
Exfiltration Over C2 Channel
Indicator Removal on Host: File Deletion
Scheduled Task/Job
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Mobile Device Security and Monitoring
Control ID: Device Security - Advanced
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.02(b)
Digital Operational Resilience Act (DORA) – ICT Third-Party Risk Management
Control ID: Article 8
General Data Protection Regulation (GDPR) – Security of Processing
Control ID: Article 32
ISO 27001:2022 – Information Security in Project Management
Control ID: A.8.24
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Pegasus zero-click mobile spyware targeting political activists creates severe surveillance risks for government communications, requiring enhanced mobile security and encrypted traffic protection.
Higher Education/Acadamia
Student movement members infected with Pegasus spyware expose academic institutions to targeted surveillance campaigns, necessitating mobile device management and threat detection capabilities.
Political Organization
Opposition politicians and activists compromised by NSO Group spyware demonstrate critical vulnerabilities in political communications requiring zero trust segmentation and anomaly detection.
Broadcast Media
Serbian media channels broadcasting private communications from compromised devices highlights journalism sector exposure to spyware-enabled surveillance and data exfiltration attacks.
Sources
- Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhonehttps://thehackernews.com/2026/09/pegasus-zero-click-spyware-exploit.htmlVerified
- Pegasus Spyware Infection of Serbian Activisthttps://citizenlab.ca/research/pegasus-spyware-infection-of-serbian-activist/Verified
- Apple Security Update iOS 18.4.1https://support.apple.com/en-us/HT214084Verified
- SHARE Foundation Report on Serbian Spyware Targetinghttps://sharefoundation.info/en/share-foundation-students-and-opposition-politicians-targeted-by-spyware/Verified
- Apple Warns Users in 110 Countries of Mercenary Spyware Attackshttps://thehackernews.com/2026/08/apple-warns-users-in-110-countries-they.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this Pegasus mobile spyware attack by constraining lateral access to cloud infrastructure and limiting command & control communications through segmented network policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Would likely have constrained the spyware's ability to establish connectivity to cloud-hosted command infrastructure through identity-aware access controls and fabric-level visibility monitoring
Control: Zero Trust Segmentation
Mitigation: May have reduced the scope of network resources accessible from the compromised device by limiting trusted network segments available to mobile endpoints through microsegmentation policies
Control: East-West Traffic Security
Mitigation: Could have limited the spyware's ability to reach additional network resources and cloud services by enforcing east-west traffic inspection and workload isolation policies
Control: Multicloud Visibility & Control
Mitigation: Would likely have constrained command and control communications by providing visibility into cross-cloud traffic patterns and enabling policy enforcement across distributed infrastructure environments
Control: Egress Security & Policy Enforcement
Mitigation: May have reduced the volume and scope of data exfiltration by enforcing egress policies that limit outbound data flows and restrict unauthorized external communications from network segments
Residual surveillance capabilities would likely be constrained to local device data with reduced ability to correlate information through cloud services or establish persistent infrastructure access for ongoing monitoring operations
Impact at a Glance
Affected Business Functions
- Political Advocacy
- Student Movement Organization
- Opposition Campaign Activities
- Secure Communications
Estimated downtime: N/A
Estimated loss: N/A
Comprehensive surveillance data including private communications, location tracking, contact lists, and personal activities of Serbian student movement members and political opposition figures during election period
Recommended Actions
Key Takeaways & Next Steps
- • Implement encrypted traffic inspection and anomaly detection to identify suspicious mobile device communications patterns indicating spyware activity
- • Deploy zero trust segmentation to limit device access to sensitive organizational resources and prevent lateral movement from compromised endpoints
- • Establish egress security controls with policy enforcement to detect and block unauthorized data exfiltration from mobile devices to external command and control infrastructure
- • Enable multicloud visibility and control capabilities to monitor for anomalous mobile device traffic patterns and repeated suspicious connections
- • Activate threat detection and anomaly response systems to baseline normal mobile communication behavior and alert on covert channel usage indicative of advanced spyware



