Executive Summary

In 2024, Serbian government authorities conducted systematic surveillance operations against student activists and political opposition using Pegasus and NoviSpy spyware. The SHARE Foundation, in collaboration with Amnesty International and The Citizen Lab, discovered infections on activists' phones, with evidence linking NoviSpy deployments directly to Serbian state authorities. The campaign targeted individuals ahead of elections, representing a coordinated effort to suppress political dissent through digital surveillance. This surveillance operation has prompted 29 European Parliament members to demand delays in Serbia's EU accession process until a full investigation is completed and rule-of-law accountability is established.

This incident exemplifies the growing trend of nation-state actors weaponizing commercial spyware against civil society, particularly in countries seeking international legitimacy while simultaneously suppressing domestic opposition through sophisticated surveillance technologies.

Why This Matters Now

Government spyware abuse is escalating globally, with authoritarian regimes increasingly using commercial surveillance tools to silence opposition while pursuing international partnerships, forcing democratic institutions to confront the intersection of cybersecurity and human rights in diplomatic relations.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Serbian authorities deployed both Pegasus and NoviSpy spyware against student activists and political opposition members, with evidence directly linking NoviSpy infections to government operations.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have constrained the Serbian government's spyware campaign by limiting lateral movement and reducing the blast radius of surveillance across victim networks and cloud services.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud workload segmentation would likely have limited the spyware's ability to reach connected cloud services and infrastructure used by activist organizations

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation policies would likely have constrained the spyware's ability to escalate privileges across connected cloud resources and networked services even with root device access

Lateral Movement

Control: East-West Traffic Security

Mitigation: Network segmentation controls would likely have reduced lateral movement between cloud workloads and services, limiting the spyware's reach across organizational infrastructure and communication platforms

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility across cloud environments would likely have detected anomalous outbound communications patterns and unauthorized connections to government surveillance infrastructure from compromised systems

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely have constrained data exfiltration by blocking unauthorized outbound transfers to government surveillance infrastructure and limiting the volume of sensitive data compromised

Impact (Mitigations)

While the overall political surveillance campaign would likely have continued, the reduced scope of compromised communications and constrained data collection could have limited the government's intelligence gathering capabilities

Impact at a Glance

Affected Business Functions

  • Political Opposition Activities
  • Civil Society Organizations
  • Student Activist Groups
  • Democratic Electoral Processes
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Personal communications, location data, and private information of Serbian student activists and political opposition members were compromised through Pegasus and NoviSpy spyware infections. The surveillance targeted individuals engaged in democratic political activities.

Recommended Actions

  • Deploy comprehensive egress security and policy enforcement to detect and block unauthorized data exfiltration from compromised devices to external command infrastructure
  • Implement zero trust segmentation with identity-based policies to limit lateral movement from compromised endpoints to critical communications and cloud services
  • Establish multicloud visibility and control with anomaly detection capabilities to identify suspicious automation patterns and repeated malformed requests indicative of spyware C2 activity
  • Deploy inline intrusion prevention systems with signature-based detection to identify and block known spyware delivery mechanisms and exploit traffic
  • Implement encrypted traffic controls with high-performance encryption for data in transit to protect sensitive communications from surveillance even if devices are compromised

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image