NSO Group's Pegasus spyware infected the iPhone of a Serbian student activist through a zero-click iMessage exploit, according to forensic analysis by the Citizen Lab and the SHARE Foundation. The zero-click attack required no user interaction, meaning the target never clicked a link or opened a malicious file. The spyware silently compromised the device.
The infection targeted a member of Serbia's student protest movement, a politically active group that has demonstrated against government policies. The timing and targeting suggest potential surveillance linked to the activist's participation in protest activities.
Citizen Lab confirmed the attack used NSO Group's proprietary zero-click exploit chain against iMessage, Apple's default messaging service. This attack vector bypasses iOS security protections that normally require user action to trigger infection. The zero-click method represents the highest tier of iPhone attack sophistication available to state-sponsored actors.
NSO Group, an Israeli surveillance firm, markets Pegasus exclusively to government clients and law enforcement agencies. The company claims its tools target terrorism and serious crime. However, Citizen Lab and human rights organizations have documented repeated cases of Pegasus targeting journalists, activists, dissidents, and political opposition figures across multiple countries. Previous documented uses include targeting Moroccan journalists, Palestinian civil society members, and Mexican anti-corruption investigators.
Pegasus performs extensive device surveillance once installed. The spyware captures call recordings, text messages, email, photos, and location data. It activates microphones and cameras remotely. It extracts passwords and encryption keys from other applications. Target device owners remain unaware of the infection.
Serbia has experienced significant government pressure on independent media and civil society organizations. The student movement represents rare domestic opposition to government policies. Targeting activists through Pegasus suggests state-level surveillance infrastructure deployment within Serbia, whether by Serbian authorities, a neighboring country, or another government client of NSO Group.
Apple patched the specific zero-click iMessage vulnerability exploited in this attack. However, NSO Group routinely develops new exploit chains targeting iOS. Security researchers estimate multiple zero-day vulnerabilities exist in active circulation among state-sponsored threat actors. Apple released iOS security updates addressing the vulnerability, but organizations and individuals must ensure devices receive the latest patches.
The Citizen Lab investigation provides forensic evidence documenting another Pegasus deployment against political activists. These findings reinforce concerns about NSO Group's role in global surveillance infrastructure targeting protected speech and association. The U.S. Department of Commerce placed NSO Group on the Entity List in 2021, restricting U.S. companies from doing business with the firm. However, NSO Group continues operations through its government clientele.
Implications extend beyond Serbia. The confirmed zero-click capability demonstrates that state-sponsored actors maintain advanced iPhone exploitation methods against targets in specific countries. Activists, journalists, and opposition figures worldwide face heightened surveillance risk. Organizations supporting vulnerable populations should implement endpoint detection systems and conduct device forensics when compromise is suspected.
The case underscores the asymmetry between commercial security defenses and state-level offensive capabilities. No consumer protection mechanism reliably defends against zero-click exploits deployed by resourced adversaries. Mitigation focuses on rapid patching, network segmentation for sensitive devices, and forensic capability to detect post-compromise indicators.
