hacker-news · Crawled Sep 3, 2026

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

1 Malware
Read original article ↗

AI Summary

A member of Serbia's student protest movement had their iPhone infected with NSO Group's Pegasus spyware via an iMessage zero-click exploit between December 2025 and January 2026. The exploit has since been patched in iOS 18.4.1. At least 14 individuals in Serbia, including activists and opposition figures, have been targeted with advanced spyware in 2026, coinciding with local elections. A new variant of NoviSpy Android spyware was also identified, suggesting ongoing surveillance operations by Serbian authorities or affiliated actors.

AI-extracted · verify before operational use

Extracted Entities 1 found

MITRE ATT&CK TTPs 3 techniques