Pegasus Spyware Hit a Serbian Student Activist's iPhone Through a Silent iMessage Attack
Citizen Lab says a zero-click exploit planted NSO Group's Pegasus on the phone of a member of Serbia's student protest movement, with no tap or click required.

Key points
- Citizen Lab and the SHARE Foundation confirmed Pegasus spyware on the iPhone of a Serbian student protest movement member.
- The infection used an iMessage zero-click exploit, meaning the victim never had to open a link or tap anything.
- The spyware is made by Israel's NSO Group, which sells only to government customers.
- Researchers found high-confidence indicators pointing to the Pegasus toolkit.
- The case adds to a pattern of Pegasus being used against activists and journalists in Serbia.
A member of Serbia's student protest movement had their iPhone secretly infected with Pegasus, the government-grade spyware made by Israel's NSO Group, according to new findings from the Citizen Lab working with Belgrade digital rights group the SHARE Foundation.
The attack used what researchers call a zero-click exploit. That means the victim did not have to tap a link, open an attachment, or do anything at all. A booby-trapped iMessage arrived, and the phone was taken over in the background.
"Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," Citizen Lab wrote. The researchers said they found high-confidence indicators of the Pegasus toolkit on the device.
The case was first reported by The Hacker News.
What is Pegasus, in plain English?
Pegasus is spyware sold by NSO Group to government agencies. Once installed on a phone, it can read messages, listen to calls, switch on the microphone and camera, and pull location data. It leaves almost no trace a normal user could spot.
NSO says it only sells to vetted state customers for serious crime and counter-terrorism work. Human rights groups have documented years of cases where the same tool has landed on the phones of journalists, lawyers, and opposition activists.
Who was targeted?
The victim is a member of the student-led protest movement that has driven mass demonstrations across Serbia over the past year. Citizen Lab did not name the individual. The infection is the latest in a run of Pegasus cases tied to Serbian civil society.
| Detail | What we know |
|---|---|
| Victim | Member of Serbia's student protest movement |
| Spyware | Pegasus, made by NSO Group |
| Delivery | Zero-click exploit over iMessage |
| Device | iPhone |
| Investigators | Citizen Lab and SHARE Foundation |
How does a zero-click attack even work?
A zero-click attack abuses a bug in software that processes incoming data automatically. On an iPhone, iMessage previews images, files and other content the moment they arrive. If attackers find a flaw in that processing code, they can craft a message that quietly runs their own code on your phone the second it lands.
No warning. No prompt. Nothing to click through.
Apple has patched several of these bugs over the past few years, often in emergency updates. It has also rolled out Lockdown Mode, a stripped-back setting that turns off many of the features Pegasus-style attacks rely on.
Who is investigating, and what happens next?
Citizen Lab, based at the University of Toronto, is the group that has repeatedly caught Pegasus in the wild. The SHARE Foundation handles digital rights casework inside Serbia. Neither body is a regulator, but their forensic reports have fed into investigations by the European Data Protection Supervisor and national data protection authorities across the EU.
Serbia's own Commissioner for Information of Public Importance and Personal Data Protection has jurisdiction over unlawful surveillance of Serbian citizens. Previous Pegasus findings in the country have gone unanswered by authorities.
NSO Group has consistently said its products are sold only to legitimate government clients and that misuse is investigated.
What should ordinary iPhone users do?
Most people are not Pegasus targets. The tool is expensive and reserved for people governments care about: activists, journalists, dissidents, senior officials. Still, a few sensible steps apply to anyone worried about phone spying.
Keep iOS on the latest version. Restart your phone daily, which can flush some spyware from memory. If you are an activist, journalist, or work in politically sensitive fields, turn on Lockdown Mode and consider Apple's Threat Notifications programme.
If you get a state-sponsored attack notification from Apple, take it seriously and contact a group like Access Now's Digital Security Helpline.



