The SHARE Foundation identifies the largest documented wave of mercenary spyware infections targeting Serbian student activists
The SHARE Foundation reported that at least 14 individuals from Serbian civil society, including student activists and a member of parliament, were targeted by advanced mercenary spyware. This represents the largest documented wave of such surveillance in Serbia to date. The infections were discovered following Apple notifications to users in 110 countries that they had likely been victims of spyware. Forensic analysis by the University of Toronto’s Citizen Lab confirmed that a student activist was infected with NSO Group’s Pegasus spyware via a zero-click exploit between December 2025 and January 2026. This spyware provides attackers with total access to a device's private data, including notes, pictures, and encrypted messages, and can covertly enable the microphone and camera. While the SHARE Foundation noted that the timing of these infections coincided with local elections, the Serbian government denied that the students were specifically spied on. Parliamentary speaker Ana Brnabić stated she did not believe a single word of the claims. Additionally, Amnesty International confirmed that two devices were infected with a new version of NoviSpy spyware. Evidence suggests these infections were carried out by Serbian authorities during detention.
Sources
-
Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist
The Citizen Lab
-
Serbians targeted with spyware in country’s ‘largest documented wave of surveillance’
The Guardian