September 3, 2026
Fool’s guide to Pegasus zero-click and studnet protests
Following a train station canopy collapsing in 2024 that killed 16 people, a strong student led pro democracy movement began challenging…

By KN
1 min read
Following a train station canopy collapsing in 2024 that killed 16 people, a strong student led pro democracy movement began challenging President Aleksander Vucic's ruling party. Following this rise in protest cases of Serbia's student protest members have had devices infected with NSO group's (an Israeli cyber-intelligence firm ) Pegasus spyware, that has been delivered via an IMessage zero-click exploit.
Based on forensic findings from citizen lab and the SHARE foundation, investigators were able to confirm device compromise between December 2025 and January 2026, exploiting an exploit chain that was patched by Apple in IOS 18.4.1.
These cases build a pattern of surveillance in Serbia. Several individuals, ranging from student activists, opposition figures and a member of parliament have been targeted with advanced spyware attacks since 2026. The SHARE foundation has noted that the timing of these attacks coincided with local elections on March 29, 2026 which raises concerns about politically motivated repression.
Additionally a second student activist had their device compromised with a new variant of NoviSpy, an android based spyware that has been previously linked to Serbian authorities. Amnesty international's security lab, have been reported saying the updated version was specifically designed to evade detection, additionally the malware strain was installed after the victim's phone was confiscated during police questioning.
Exploit:
Pegasus:
This is a sophisticated spyware, it works via gaining root-level access, bypassing Apple's security layers to capture messages, calls, photos, microphone audio and encrypted app data, which it sends to a remote command and control centre server via encrypted channels, to make detection difficult.
IMessage zero-click:
A vulnerability within how imessage processes incoming data, that allows for the automatic triggering of code hidden within messages and images. This works due to iphones trying to interpret message content before displaying as result, messages contain code that would overflow memory buffers thus allowing the message to escape the "blastDoor" sandbox and execute commands.
NoviSpy:
This is an android-based surveillance tool that has been linked to regional law-enforcement and state-sponsored operations. This tool requires physical access for installation.