Skip to main content
LiMP VPN
All news

Pegasus Zero-Click Hits Serbian Students via iMessage

Pegasus Zero-Click Hits Serbian Students via iMessage

In short: Citizen Lab and Serbia's SHARE Foundation confirmed that a member of Serbia's student protest movement had their iPhone infected with Pegasus spyware via a zero-click iMessage exploit — no tap required, no link to click. Since early 2026, at least 14 students, activists and opposition politicians in Serbia have been targeted. Update to iOS 18.4.1 and enable Lockdown Mode if you are at elevated risk.

What happened

On September 2, 2026, Citizen Lab — the independent research lab at the University of Toronto — together with Serbian human rights organisation SHARE Foundation published a report documenting a fresh wave of surveillance using commercial spyware. Researchers confirmed that a member of Serbia's student protest movement had their iPhone infected with Pegasus, the powerful surveillance tool developed by Israeli company NSO Group.

The attack vector was a zero-click iMessage exploit, meaning the device was compromised without any action from the target. Infection was confirmed during a window of December 2025 through January 2026. Citizen Lab describes this as part of a broader surveillance campaign: since early 2026, Apple automatically sent Threat Notifications to at least 14 individuals in Serbia — students, civil society members, an opposition Member of Parliament, and local councilors. The timeline overlaps with Serbia's local elections on March 29, 2026.

Citizen Lab describes this as the largest documented surveillance wave in Serbia to date. The organisation had already documented Pegasus use against Serbian journalists and activists in 2024, but the current campaign is notably larger and targets the student movement for the first time. For more on mobile security threats, visit the LiMP VPN security blog.

What Pegasus can do: full device takeover

Pegasus is among the most capable commercial surveillance tools ever documented. Once installed, an operator can do "anything the user can do" — and more:

  • Read encrypted messages. Pegasus accesses Signal, WhatsApp, Telegram and other chats before encryption, reading content directly from memory or the screen.
  • Access photos, notes and documents. The spyware reaches the device file system and any cloud accounts synced to the phone.
  • Silently activate the camera and microphone. The device becomes a real-time listening and recording tool with no visible indicator to the victim.
  • Track precise location. Pegasus logs the target's movements continuously and with high accuracy.
  • Capture passwords. The tool records keystrokes and intercepts authentication credentials before they are encrypted.

All of this happens silently — the battery may drain a little faster, but there are no visible alerts or pop-ups on the infected device.

Why zero-click attacks are so dangerous

Traditional phishing requires a victim to click a link or open a file. A zero-click exploit removes even that barrier: the attack fires when a specially crafted message arrives in iMessage — no user interaction needed whatsoever.

The specific vulnerability used in this campaign was patched by Apple in iOS 18.4.1, released in April 2025. However, Citizen Lab notes that the confirmed infection window "does not preclude the possibility of additional infections" before or after that period — and NSO Group continuously develops new attack vectors.

NoviSpy: Android is also at risk

The same investigation uncovered a new version of NoviSpy — an Android spyware strain — on a separate student activist's phone. That device had previously been confiscated during a police questioning session. Physical access during detention is a classic NoviSpy installation vector.

NoviSpy is a lesser-known but equally dangerous surveillance tool: it records calls, intercepts messages, and exfiltrates data to a remote server. This finding shows the surveillance campaign operates across platforms simultaneously — iOS targeted via zero-click exploit, Android targeted via physical device compromise during detention.

Defending against physical device infection is a separate challenge. Start with a strong PIN and full-disk encryption; for network-level privacy, LiMP VPN's privacy features add an important additional layer.

How to protect yourself

There is no absolute defence against NSO-tier spyware, but several measures significantly reduce risk:

  • Update iOS to the latest version. The zero-click exploit used in this campaign is patched in iOS 18.4.1. Keeping software current is the single most effective defence against known vulnerabilities.
  • Enable Lockdown Mode on iPhone. This mode substantially restricts iMessage and other attack surfaces, blocking the majority of known zero-click vectors. It is designed precisely for people at elevated risk.
  • Enable Google Advanced Protection on Android. Google's hardening programme restricts app installation and data access in ways that limit spyware attack surfaces.
  • Never leave your device unattended during searches or detentions. Physical access is NoviSpy's primary installation vector. If you face high-risk situations, consider a separate clean device for interactions with authorities.
  • Encrypt your network traffic with LiMP VPN. A VPN does not block Pegasus — which operates at the device level — but the LiMP VPN app encrypts all outbound traffic and hides it from network observers and your ISP. This matters most on public networks where interception is easiest.
  • If you receive an Apple Threat Notification, seek expert help. Citizen Lab, Access Now's Digital Security Helpline, and SHARE Foundation offer free assistance to individuals who receive these warnings.

Sources

Pegasus Zero-Click Hits Serbian Students via iMessage