Executive Summary
In 2024, Serbian government authorities conducted systematic surveillance operations against student activists and political opposition using Pegasus and NoviSpy spyware. The SHARE Foundation, in collaboration with Amnesty International and The Citizen Lab, discovered infections on activists' phones, with evidence linking NoviSpy deployments directly to Serbian state authorities. The campaign targeted individuals ahead of elections, representing a coordinated effort to suppress political dissent through digital surveillance. This surveillance operation has prompted 29 European Parliament members to demand delays in Serbia's EU accession process until a full investigation is completed and rule-of-law accountability is established.
This incident exemplifies the growing trend of nation-state actors weaponizing commercial spyware against civil society, particularly in countries seeking international legitimacy while simultaneously suppressing domestic opposition through sophisticated surveillance technologies.
Why This Matters Now
Government spyware abuse is escalating globally, with authoritarian regimes increasingly using commercial surveillance tools to silence opposition while pursuing international partnerships, forcing democratic institutions to confront the intersection of cybersecurity and human rights in diplomatic relations.
Attack Path Analysis
Serbian government authorities deployed spyware (Pegasus and NoviSpy) to target student activists and political opposition through initial device compromise, escalated privileges to achieve persistent access, moved laterally across victim networks, established command and control channels for ongoing surveillance, exfiltrated sensitive communications and activities, and ultimately achieved the strategic impact of suppressing democratic opposition ahead of elections.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Serbian government authorities initiated targeted spyware deployment against student activists and political opposition using Pegasus and NoviSpy implants through likely phishing, malicious links, or zero-day exploits to gain initial device access
MITRE ATT&CK® Techniques
Spearphishing Attachment
Spearphishing Link
Exploitation for Client Execution
Launch Agent
Process Injection
Keylogging
Screen Capture
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
EU General Data Protection Regulation (GDPR) – Lawfulness, fairness and transparency
Control ID: Article 5(1)(a)
NIS2 Directive – Cybersecurity measures
Control ID: Article 21
CISA Zero Trust Maturity Model 2.0 – Device compliance and health monitoring
Control ID: Device Security - Advanced
Digital Operational Resilience Act (DORA) – Identification and classification of ICT risk
Control ID: Article 8
PCI DSS 4.0 – Deploy a change- and tamper-detection mechanism
Control ID: 11.5.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Serbian government's use of Pegasus and NoviSpy spyware against activists demonstrates state-sponsored surveillance capabilities threatening democratic processes and citizen privacy rights.
Political Organization
Spyware targeting political opposition creates systematic dismantling of democratic participation, requiring enhanced encrypted communications and zero trust segmentation for campaign security.
International Affairs
EU accession negotiations impacted by surveillance revelations, highlighting need for diplomatic communications security and compliance with democratic governance standards internationally.
Computer/Network Security
Detection of sophisticated spyware infections demonstrates advanced persistent threats requiring enhanced threat detection, anomaly response capabilities, and encrypted traffic protection solutions.
Sources
- European parliament members call for slowdown of Serbia’s EU entry over spyware usehttps://cyberscoop.com/eu-parliament-serbia-accession-spyware-demands/Verified
- SHARE Foundation Report on Spyware Infections in Serbiahttps://www.sharedefend.org/Verified
- Amnesty International - Pegasus Spyware Researchhttps://www.amnesty.org/en/latest/research/2021/07/the-pegasus-project/Verified
- The Citizen Lab - University of Toronto Spyware Researchhttps://citizenlab.ca/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained the Serbian government's spyware campaign by limiting lateral movement and reducing the blast radius of surveillance across victim networks and cloud services.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud workload segmentation would likely have limited the spyware's ability to reach connected cloud services and infrastructure used by activist organizations
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely have constrained the spyware's ability to escalate privileges across connected cloud resources and networked services even with root device access
Control: East-West Traffic Security
Mitigation: Network segmentation controls would likely have reduced lateral movement between cloud workloads and services, limiting the spyware's reach across organizational infrastructure and communication platforms
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility across cloud environments would likely have detected anomalous outbound communications patterns and unauthorized connections to government surveillance infrastructure from compromised systems
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have constrained data exfiltration by blocking unauthorized outbound transfers to government surveillance infrastructure and limiting the volume of sensitive data compromised
While the overall political surveillance campaign would likely have continued, the reduced scope of compromised communications and constrained data collection could have limited the government's intelligence gathering capabilities
Impact at a Glance
Affected Business Functions
- Political Opposition Activities
- Civil Society Organizations
- Student Activist Groups
- Democratic Electoral Processes
Estimated downtime: N/A
Estimated loss: N/A
Personal communications, location data, and private information of Serbian student activists and political opposition members were compromised through Pegasus and NoviSpy spyware infections. The surveillance targeted individuals engaged in democratic political activities.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy comprehensive egress security and policy enforcement to detect and block unauthorized data exfiltration from compromised devices to external command infrastructure
- • Implement zero trust segmentation with identity-based policies to limit lateral movement from compromised endpoints to critical communications and cloud services
- • Establish multicloud visibility and control with anomaly detection capabilities to identify suspicious automation patterns and repeated malformed requests indicative of spyware C2 activity
- • Deploy inline intrusion prevention systems with signature-based detection to identify and block known spyware delivery mechanisms and exploit traffic
- • Implement encrypted traffic controls with high-performance encryption for data in transit to protect sensitive communications from surveillance even if devices are compromised



