Executive Summary

In December 2025 through January 2026, NSO Group's Pegasus spyware infected the iPhone of a Serbian student protest movement member using a zero-click iMessage exploit. The attack was part of a broader surveillance campaign targeting at least 14 Serbian activists, opposition politicians, and student leaders coinciding with March 2026 local elections. Citizen Lab and SHARE Foundation confirmed the infection, while a separate incident involved NoviSpy Android malware deployed during police detention of another student activist.

This incident highlights the escalating use of commercial spyware against civil society, particularly as authoritarian governments increasingly weaponize surveillance technology to suppress political dissent and monitor opposition movements ahead of critical elections.

Why This Matters Now

Commercial spyware attacks against civil society are surging globally, with governments deploying zero-click exploits to suppress political opposition. This Serbian case demonstrates how surveillance technology threatens democratic participation and requires immediate defensive measures.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The infection used a zero-click iMessage exploit that required no user interaction, automatically compromising the device when messages were received.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the blast radius of this Pegasus mobile spyware attack by constraining lateral access to cloud infrastructure and limiting command & control communications through segmented network policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Would likely have constrained the spyware's ability to establish connectivity to cloud-hosted command infrastructure through identity-aware access controls and fabric-level visibility monitoring

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: May have reduced the scope of network resources accessible from the compromised device by limiting trusted network segments available to mobile endpoints through microsegmentation policies

Lateral Movement

Control: East-West Traffic Security

Mitigation: Could have limited the spyware's ability to reach additional network resources and cloud services by enforcing east-west traffic inspection and workload isolation policies

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Would likely have constrained command and control communications by providing visibility into cross-cloud traffic patterns and enabling policy enforcement across distributed infrastructure environments

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: May have reduced the volume and scope of data exfiltration by enforcing egress policies that limit outbound data flows and restrict unauthorized external communications from network segments

Impact (Mitigations)

Residual surveillance capabilities would likely be constrained to local device data with reduced ability to correlate information through cloud services or establish persistent infrastructure access for ongoing monitoring operations

Impact at a Glance

Affected Business Functions

  • Political Advocacy
  • Student Movement Organization
  • Opposition Campaign Activities
  • Secure Communications
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Comprehensive surveillance data including private communications, location tracking, contact lists, and personal activities of Serbian student movement members and political opposition figures during election period

Recommended Actions

  • Implement encrypted traffic inspection and anomaly detection to identify suspicious mobile device communications patterns indicating spyware activity
  • Deploy zero trust segmentation to limit device access to sensitive organizational resources and prevent lateral movement from compromised endpoints
  • Establish egress security controls with policy enforcement to detect and block unauthorized data exfiltration from mobile devices to external command and control infrastructure
  • Enable multicloud visibility and control capabilities to monitor for anomalous mobile device traffic patterns and repeated suspicious connections
  • Activate threat detection and anomaly response systems to baseline normal mobile communication behavior and alert on covert channel usage indicative of advanced spyware

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image