Key facts
- At least 14 individuals in Serbia's civil society were targeted with advanced spyware.
- The SHARE Foundation discovered the spyware infections in August.
- The targeting occurred ahead of local elections held on March 29.
- Confirmed targets include students, activists, and opposition party members.
- Pegasus and NoviSpy-like malware were identified on targeted devices.
At least 14 individuals within Serbia's civil society were targeted with advanced spyware in the lead-up to local elections in March, according to a statement from the digital rights group SHARE Foundation. This marks the largest documented wave of such infections in Serbia to date, offering insight into the use of invasive spyware against students and political opposition members.
The confirmed cases include members of a student movement, activists, opposition party members in parliament, and a local councilor. At least one device was targeted with Pegasus spyware, developed by Israel's NSO Group, while at least two devices were infected with malware similar to NoviSpy. Reuters could not independently determine who was responsible for the alleged infections.
NSO Group has stated it only sells to governments and may suspend or terminate relationships with clients for noncompliance. In one instance, a zero-click version of Pegasus was used on a student movement member's device, requiring no user interaction. NoviSpy was found on another student activist's phone, which had previously been confiscated by police.
The targeting coincided with the March 29 local elections, viewed as a test for student-backed opposition groups. SHARE Foundation suggests this digital targeting may foreshadow similar actions for the parliamentary elections scheduled for October. Donncha Ó Cearbhaill of Amnesty International highlighted that Serbian student activists continue to be targeted with invasive spyware. Citizen Lab researchers noted the Pegasus implant was placed on at least one student's phone between December 2025 and January 2026, though Apple's security updates have since neutralized the spyware. Apple confirmed sending threat notifications to targeted users in 110 countries on August 13, part of broader notifications to users in over 150 countries.