At least 14 people from across Serbian civil society were targeted with advanced spyware earlier this year in what the digital rights group Share Foundation said was the largest documented wave of such infection in Serbia to date.
The wave of spyware infections was discovered in August after Apple notified people in 110 countries that they had probably been victims of mercenary spyware.
The Citizen Lab , which carries out forensic analyses of spyware attacks, released an analysis on Wednesday showing that at least one of the Serbians had been targeted with the NSO Group’s Pegasus spyware, which would have given the attacker “total access to the device”.
Share said those targeted included members of a Serbian student movement that has been a thorn in the side of the government of Aleksandar Vučić since 2024. Coalescing out of countrywide protests that followed the collapse of a train station that winter, it is one of the largest student movements in Europe.
Vučić has been in power for more than a decade, during which time critics have said he has overseen a hollowing-out of institutions while steering the country closer to Moscow .
There is no evidence that Vučić’s government was the entity that targeted the students with spyware. In an interview with Euronews Serbia TV on Wednesday, Ana Brnabić, the parliamentary speaker and a ranking member of the ruling Serbian Progressive party, denied that students had been spied on. “Absolutely not,” she said. “I do not believe a single word they’ve [students, Share] said.”
Share said the timing – during March’s local elections – may have been a practice run before snap elections set for this October.
“This is the largest documented wave of surveillance in Serbia so far,” said Andrijana Ristic, a policy adviser at Share. “We imagine … that the local elections were basically used as a test for the ruling party to see [the spyware’s] strengths, but also to see the amount of pressure they are able to exert over the students and the opposition.”
John Scott-Railton, a senior researcher at the Citizen Lab, said: “Our forensic findings, and this fresh wave of Apple threat notifications reveal that Serbia’s peaceful pro-democracy movement is being aggressively targeted with mercenary spyware ahead of key 2026 election cycles.”
Milica Popović, one of the students who was targeted, called the attacks “cruel”. She said: “Thinking that someone may have entered my private space without my knowledge made me feel so exposed.” But, she said, the attack, as uncomfortable as it was, would not deter her or the student movement. “If their intention was to frighten us, or make us stop, it will not work.”
NSO Group, which makes Pegasus , a spyware that has been leveraged by authoritarian states to target journalists, human rights campaigners and dissidents, began as an Israeli company with close ties to the military.
It is now under US ownership , and appears to be searching for a way into the US market, including through efforts to get off the US Commerce Department’s blacklist. However, this and other incidents will raise questions about what has been described as their attempt to rebrand as an “ethical spyware company”.
NSO Group has been permanently barred by a US court from targeting WhatsApp users and Meta products. It is unclear if this most recent Pegasus attack happened via WhatsApp.
“Today, Pegasus is still being used to hack people campaigning for democracy. NSO spent a decade promising reform, yet their spyware is still an instrument of political repression,” said Railton.
The wave of spyware infections was discovered in August after Apple notified people in 110 countries that they had probably been victims of mercenary spyware.
This report is published with credit to theguardian.com. Full available text from the wire is above. Read on theguardian.com →
Source: theguardian.com · Aisha Down. Published 3 Sept 2026, 05:48 pm.