Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and Student Protesters

Serbian Authorities Deploy Pegasus and NoviSpy Spyware (TL-2026-2316) is a high-severity advanced persistent threat campaign scored CVSS 9.8, first published 2026-09-03 and last reviewed 2026-09-05. It is attributed to Serbia Security Information Agency (Serbia) with high confidence, affects Apple iOS / iPadOS (iPhone), references 6 CVEs (CVE-2025-31200, CVE-2025-31201, CVE-2024-53104), maps to 31 MITRE ATT&CK techniques (T1398, T1404, T1409), and is covered by 9 detection rules and 37 indicators of compromise.

Key facts for TL-2026-2316

Threat ID
TL-2026-2316
Severity
HIGH
CVSS
9.8
Status
ACTIVE
Category
APT
First published
2026-09-03
Last reviewed
2026-09-05
Attribution
Serbia Security Information Agency
Attribution confidence
HIGH
Nation-state nexus
Serbia
Motivation
ESPIONAGE
Target sectors
government administration, news - media, ngo, civil society, political opposition
Target regions
Europe, Balkans, serbia
Detection rules
9
Indicators of compromise
37
Updates
2026-09-05 · 2 updates · revalidated 2× · latest source

Malware and tooling in Serbian Authorities Deploy Pegasus and NoviSpy Spyware

Malware and tooling: Chrysaor, NoviSpy, Cellebrite UFED, Pegasus operator infrastructure (NSO Group)

Serbian authorities used NSO Group's Pegasus (iMessage zero-click) and the domestically-linked NoviSpy Android spyware (Cellebrite UFED-enabled physical install) to target at least 14 Serbians since December 2025, including MP Radomir Lazović, student activist Jelena Kontić, a local councilor, and journalists. Citizen Lab and Amnesty International's Security Lab confirmed the infections; Apple issued threat notifications to 12 victims in August 2026. Serbia's BIA denies involvement.

How Serbian Authorities Deploy Pegasus and NoviSpy Spyware works

Since December 2025, at least 14 Serbian civil society members, opposition figures, and journalists have been targeted with commercial spyware in a campaign that SHARE Foundation calls the largest documented wave of surveillance in the country to date. A member of Serbia's student protest movement had their iPhone infected with NSO Group's Pegasus via an iMessage zero-click exploit requiring no user interaction; Citizen Lab confirmed the infection with high confidence and tied the exploit to the vulnerability class Apple closed in iOS 18.4.1. Two additional devices were confirmed infected with a new variant of NoviSpy, a bespoke Android spyware system first documented by Amnesty International in December 2024 and previously linked by forensic evidence (C2 configuration data) to a BIA (Bezbednosno-informativna agencija, Serbia's Security Information Agency) employee with a history of procuring Hacking Team Android spyware. Apple sent mercenary-spyware threat notifications to 12 of the 14 known victims in August 2026, prompting several to come forward publicly at a September 2, 2026 SHARE Foundation press conference, including student activist Jelena Kontić; on September 3, Green-Left Front MP Radomir Lazović confirmed he was also targeted.

The campaign continues a documented pattern stretching back to November 2023, when Amnesty, Access Now, SHARE Foundation, and Citizen Lab first jointly confirmed zero-click Pegasus infections of Serbian civil society members. In December 2024, Amnesty's 'A Digital Prison' report revealed that Serbian police and BIA had been using Cellebrite UFED forensic-extraction hardware to unlock confiscated Android phones during detentions and covertly install NoviSpy — documenting cases against journalist Slaviša Milanov and a Krokodil NGO activist. In February 2025, Amnesty disclosed that this install chain relied on a then-undisclosed Cellebrite zero-day (a Linux kernel USB Video Class privilege-escalation bug, CVE-2024-53104, alongside related USB-stack flaws CVE-2024-53197 and CVE-2024-50302) used against a 23-year-old student activist's Samsung Galaxy A32; Cellebrite subsequently cut off the responsible Serbian customer. A parallel Qualcomm DSP driver use-after-free (CVE-2024-43047, adsprpc) was also documented in NoviSpy tradecraft. In March 2025, two BIRN investigative journalists were separately targeted with Pegasus via Viber messages sent from a number linked to state operator Telekom Srbija.

The targeting has consistently coincided with Serbian electoral and protest cycles: the current wave overlaps the March 29, 2026 local elections and the anti-government student protest movement that grew out of the 2024 Novi Sad railway-station canopy collapse, and continues ahead of early parliamentary elections expected in October 2026. Serbia's BIA dismissed the allegations as 'trivial sensationalism' serving 'foreign intelligence services,' and Parliament Speaker Ana Brnabić denied state involvement, calling it implausible that a state actor using million-euro spyware would leave forensic traces. NSO Group, the Pegasus developer, has been on the U.S. Commerce Department's Entity List since November 2021 for supplying spyware used to target journalists, activists, and dissidents; it did not respond to requests for comment.

MITRE ATT&CK techniques used in TL-2026-2316

Persistence

T1398 Boot or Logon Initialization Scripts; T1541 Foreground Persistence; T1624.001 Broadcast Receivers; T1645 Compromise Client Software Binary

Privilege Escalation

T1404 Exploitation for Privilege Escalation; T1626.001 Abuse Elevation Control Mechanism

Collection

T1409 Stored Application Data; T1429 Audio Capture; T1430 Location Tracking; T1453 Abuse Accessibility Features; T1512 Video Capture; T1513 Screen Capture; T1636.002 Call Log; T1636.003 Contact List; T1636.004 SMS Messages

Credential Access

T1417 Input Capture

Discovery

T1418 Software Discovery; T1420 File and Directory Discovery; T1421 System Network Connections Discovery; T1422 System Network Configuration Discovery; T1426 System Information Discovery

Initial Access

T1456 Drive-By Compromise; T1461 Lockscreen Bypass; T1660 Phishing; T1664 Exploitation for Initial Access

Command and Control

T1481 Web Service

Defense Evasion

T1628 Hide Artifacts; T1629.001 Impair Defenses

command-and-control

T1644 Out of Band Data

Exfiltration

T1646 Exfiltration Over C2 Channel

Execution

T1658 Exploitation for Client Execution

Affected products and versions in Serbian Authorities Deploy Pegasus and NoviSpy Spyware

  • Apple — iOS / iPadOS (iPhone)
    Vulnerable versions: iOS/iPadOS prior to 18.4.1
    Fixed in: iOS 18.4.1; iPadOS 18.4.1; macOS Sequoia 15.4.1; tvOS 18.4.1; visionOS 2.4.1; watchOS 11.5
  • Google — Android (Linux kernel USB subsystem)
    Vulnerable versions: Android devices with kernels not carrying the December 2024/January 2025 upstream Linux USB fixes
    Fixed in: Android Security Bulletin, February 2025
  • Qualcomm — Snapdragon DSP driver (adsprpc)
    Vulnerable versions: Devices with unpatched adsprpc driver
    Fixed in: Qualcomm security patch for CVE-2024-43047
  • Samsung — Galaxy A32
    Vulnerable versions: Documented exploited unit (2025 Cellebrite chain case)
    Fixed in: Device patched with February 2025 Android security bulletin

Remediation for Serbian Authorities Deploy Pegasus and NoviSpy Spyware

Patches

  • Apple iOS 18.4.1 / iPadOS 18.4.1 (CVE-2025-31200, CVE-2025-31201)
  • Android Security Bulletin, February 2025 (CVE-2024-53104, CVE-2024-53197, CVE-2024-50302)
  • Qualcomm fix for CVE-2024-43047 (adsprpc use-after-free)
  • Upstream Linux kernel fixes, December 2024, for the UVC and ALSA USB-sound drivers

Immediate actions

  • Apply Apple's iOS 18.4.1+ update to close the CoreAudio/RPAC zero-click chain (CVE-2025-31200, CVE-2025-31201) and keep devices on the latest available patch
  • Enable Apple Lockdown Mode on iPhones belonging to journalists, activists, opposition politicians, and protest organizers at elevated risk
  • Apply the February 2025 Android security bulletin to remediate the Linux kernel USB (UVC/ALSA/HID) lockscreen-bypass chain (CVE-2024-53104, CVE-2024-53197, CVE-2024-50302) and the Qualcomm adsprpc fix (CVE-2024-43047)
  • Never surrender an unlocked or unattended phone during a police stop or interview; power devices off before any encounter with security services
  • Scan Android devices with AndroidQF + Mobile Verification Toolkit (MVT) against Amnesty's published NoviSpy IOC set (package names, cert hashes, sample hashes, C2 IPs)

Workarounds

  • Enable Lockdown Mode (iOS) or Advanced Protection Program (Android) for high-risk users
  • Avoid connecting devices to untrusted USB accessories or forensic docking stations; disable USB debugging
  • Treat any device confiscated by authorities, even briefly, as compromised and replace or fully re-provision it afterward

Longer-term hardening

  • Enroll high-risk individuals by default in Google's Advanced Protection Program and Apple's Lockdown Mode
  • Civil society organizations should maintain a standing digital-forensics response capability (the SHARE Foundation model) to triage Apple/Google threat notifications quickly
  • Push for export-control and procurement transparency on commercial spyware and forensic-extraction vendors (Cellebrite, NSO Group) sold to states lacking independent oversight
  • Support independent judicial oversight and public disclosure requirements for BIA/police use of intrusion and forensic-extraction tools

CVEs associated with Serbian Authorities Deploy Pegasus and NoviSpy Spyware

CVE-2025-31200, CVE-2025-31201, CVE-2024-53104, CVE-2024-53197, CVE-2024-50302, CVE-2024-43047

Weaknesses (CWE) in Serbian Authorities Deploy Pegasus and NoviSpy Spyware

CWE-787, CWE-416, CWE-119, CWE-1220, CWE-908

Timeline of Serbian Authorities Deploy Pegasus and NoviSpy Spyware

Showing the 20 most recent tracked events.

  • Qualcomm patches CVE-2024-43047, the adsprpc use-after-free zero-day exploited by Cellebrite/BIA, in its October 2024 Security Bulletin following Google Project Zero and Amnesty International collaboration.
  • Environmental activist Nikola Ristić and a Krokodil organization activist are covertly infected with NoviSpy following BIA interviews.
  • A renovated concrete canopy collapses at the Novi Sad railway station, killing 16 people and triggering the student-led protest movement later targeted by this spyware campaign.
  • Amnesty International's Security Lab publishes 'A Digital Prison,' revealing the NoviSpy Android spyware and Serbian police/BIA use of Cellebrite UFED to unlock devices of journalist Slaviša Milanov and a Krokodil NGO activist during police interviews, and publishes indicators of compromise to GitHub.
  • A 23-year-old Belgrade student protester's Samsung Galaxy A32 is compromised in roughly four minutes via Cellebrite's Turbo Link USB-emulation exploit chain (CVE-2024-53104, CVE-2024-53197, CVE-2024-50302), achieving root code execution and a full lockscreen bypass.
  • Google receives Amnesty's technical findings and begins sharing Linux kernel USB-driver fixes with Android OEM partners ahead of public disclosure.
  • Amnesty publishes a second research briefing describing a Cellebrite zero-day privilege-escalation chain (CVE-2024-53104, CVE-2024-53197, CVE-2024-50302) used to unlock a 23-year-old student activist's Samsung Galaxy A32 and attempt a NoviSpy install; Cellebrite subsequently suspends the responsible Serbian customer's access.
  • Cellebrite announces it has suspended use of its products by 'relevant customers' in Serbia following Amnesty International's disclosures of misuse.
  • Serbia's student-led protest movement reaches its peak scale, with up to 325,000 participants demonstrating against the ruling Serbian Progressive Party (SNS).
  • Amnesty and BIRN reveal that journalists Bogdana (pseudonym) and Jelena Veljković were targeted with Pegasus via Viber messages sent from a number linked to state telecom operator Telekom Srbija.
  • Apple ships iOS 18.4.1, fixing CVE-2025-31200 (CoreAudio) and CVE-2025-31201 (RPAC/PAC bypass), which Apple's own advisory said were exploited in 'an extremely sophisticated attack against specific targeted individuals.'
  • Tens of thousands protest in Novi Sad on the one-year anniversary of the railway station canopy collapse, sustaining the student-led movement that becomes the primary target of the 2026 spyware wave.
  • A member of Serbia's student protest movement is infected with Pegasus via an iMessage zero-click exploit; Citizen Lab's forensic timeline places the infection window between December 2025 and January 2026.
  • High-confidence Pegasus infection indicators on the protester's iPhone end, marking the close of the identified compromise window.
  • Serbian local elections are held; the spyware campaign intensifies around the student movement's election-monitoring and opposition campaign activity.
  • Apple sends mercenary-spyware threat notifications to 12 Serbian individuals, prompting the victims to contact the SHARE Foundation for forensic assistance.
  • SHARE Foundation holds a press conference; student activist Jelena Kontić and three other students go public, alongside confirmation that a sitting MP and a local councilor were also targeted, bringing the total to at least 14 victims since December 2025.
  • Green-Left Front MP Radomir Lazović confirms he was targeted; Serbia's BIA calls the allegations 'trivial sensationalism' and Parliament Speaker Ana Brnabić denies state involvement, while The Record publishes the consolidated investigation.
  • 29 Members of the European Parliament send a letter demanding Serbia's EU accession be slowed and conditioned on accountability, and calling on Commission President Ursula von der Leyen to cancel her planned visit to Belgrade.
  • Serbia's planned early parliamentary elections are scheduled, forming the backdrop for continued targeting risk to civil society and opposition figures.

Update history for TL-2026-2316

Sources cited for Serbian Authorities Deploy Pegasus and NoviSpy Spyware

More in apt

Detection coverage for TL-2026-2316

As of 2026-09-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2316 across Splunk SPL, Microsoft KQL and Sigma, covering 37 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats