(Adnkronos) – At least 14 people in Serbia have been targeted with advanced spyware since the beginning of the year. This was revealed by an investigation by the Share Foundation, an independent digital rights organization based in Belgrade, describing the operation as the “largest wave of surveillance documented so far in the country”.
The infections affected the devices of several members of the student movement, a parliamentary deputy, and a local city councilor, all belonging to opposition parties, explains the NGO, emphasizing that the timing coincides with the local elections held on March 29.
The Share Foundation report highlights that this type of spyware, available to government agencies and often associated with government use, allows complete access to the infected device: messages, contacts, photos, application data, and other files, as well as secret screen recordings or the activation of the microphone and camera.
In the report, the Share Foundation explains that twelve people contacted its forensic IT experts after receiving an alert on their phones indicating an ongoing spyware attack, of the kind regularly sent by Apple to alert its users subject to cyberattacks. Two international forensic IT laboratories, the Citizen Lab at the University of Toronto and Amnesty International’s Security Lab, independently confirmed the findings.
“Our forensic findings and this new wave of threat notifications from Apple reveal that the peaceful Serbian pro-democracy movement is subject to an aggressive campaign via mercenary spyware ahead of key electoral cycles in 2026,” said John Scott-Railton, senior researcher at Citizen Lab. This latter entity confirmed the use of Nso Group’s Israeli Pegasus spyware on the device belonging to a member of the student movement. The device was breached via a zero-click exploit targeting the iMessage application for iPhone: the infection therefore occurred remotely, without the user’s knowledge and without requiring any interaction.
The Security Lab, on the other hand, confirmed two other infections, caused by a new version of NoviSpy, a spyware first identified in Serbia in 2024. Share’s forensic analyses “demonstrate that Serbian students continue to be targeted with invasive Android spyware tools, installed during detention by Serbian authorities,” states Donncha Ó Cearbhaill, head of the entity, adding that the identified software was similar to NoviSpy but developed from scratch with specific measures to avoid detection by security experts.