Malware
Chrysaor
Also known as: JigglyPuff · Pegasus
Indicators of Compromise 1
MITRE ATT&CK TTPs 3
Source Articles
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
A member of Serbia's student protest movement had their iPhone infected with NSO Group's Pegasus spyware via an iMessage zero-click exploit between December 2025 and January 2026. The exploit has since been patched in iOS 18.4.1. At least 14 individuals in Serbia, including activists and opposition figures, have been targeted with advanced spyware in 2026, coinciding with local elections. A new variant of NoviSpy Android spyware was also identified, suggesting ongoing surveillance operations by Serbian authorities or affiliated actors.
hacker-news ·4w ago
European Parliament Member Investigating Spyware Was Hacked With Pegasus
Former European Parliament member Stelios Kouloglou was repeatedly targeted with Pegasus spyware during his tenure on the PEGA Committee, which investigated misuse of commercial spyware. Forensic analysis revealed two infections in October 2022 and March 2023, both exploiting a zero-click vulnerability in Apple's HomeKit (PWNYOURHOME) affecting iOS 15.5. The attacks coincided with key committee activities and may be linked to a Pegasus operator targeting multiple EU jurisdictions, possibly overlapping with a campaign against exiled journalists.
hacker-news ·3mo ago