Independent forensic analysis ties NSO Group's Pegasus and a Serbia-linked NoviSpy variant to a fourteen-target surveillance campaign against opposition politicians and student protest leaders ahead of contested elections.
Intelligence Lead
Citizen Lab and Amnesty International have confirmed that NSO Group's Pegasus spyware and a bespoke Android tool known as NoviSpy infected the devices of at least fourteen Serbian opposition politicians, civil society figures, and student protest leaders since early 2026, the largest documented mercenary-spyware campaign in the country's history. The disclosure, published 2 September, lands amid a protest cycle that has already forced one prime ministerial resignation and ahead of an election calendar in which President Aleksandar Vučić's government faces sustained pressure over corruption and rule-of-law concerns. Belgrade has dismissed the findings as sensationalism, leaving unresolved who commissioned the operation and what it signals about the durability of mercenary spyware markets despite years of sanctions.
Situation Report
Citizen Lab, working with Serbia's SHARE Foundation, forensically examined the iPhone of a member of Serbia's student protest movement after Apple issued a threat notification warning the device had been targeted by state-sponsored attackers. Analysts found high-confidence indicators that a zero-click iMessage exploit delivered Pegasus to the device between December 2025 and January 2026, an attack requiring no interaction from the target and granting the operator access to messages, camera, microphone, and location data.
SHARE Foundation's parallel investigation identified fourteen targets in total, including a sitting member of parliament, a local councilor, and multiple activists and students tied to the protest movement, in what researchers describe as the largest confirmed surveillance wave in Serbian history. Amnesty International's Security Lab separately confirmed that two additional devices carried a newly rebuilt version of NoviSpy, a bespoke Android spyware tool first documented in 2024 and previously linked by Amnesty to Serbia's Security Information Agency, the BIA.
The targeting window overlaps with Serbia's 29 March local elections and the broader protest cycle that began in late 2024 after a railway station canopy collapse in Novi Sad killed sixteen people, a disaster protesters blame on government corruption and lax construction oversight. Vučić and Serbian security officials have rejected the findings outright, calling the reporting "trivial sensationalism" and declining to confirm or deny use of either tool.
NSO Group has issued no substantive response to the specific Serbian findings. The company remains on the US Commerce Department's Entity List, restricting its access to American technology, yet continues to sell Pegasus to government clients internationally, underscoring the limited practical effect of export-control designations on the mercenary spyware trade.
Background & Context
Serbia has been the site of sustained anti-government protest since November 2024, when the collapse of a renovated railway station canopy in Novi Sad became a flashpoint for grievances over corruption, media capture, and eroding judicial independence under Vučić's decade-plus rule. The protests forced the resignation of Prime Minister Miloš Vučević and the Novi Sad mayor in January 2025 but continued into 2026 on demands for early elections and accountability.
NoviSpy first surfaced in Amnesty International's December 2024 investigation, which tied the tool to the BIA and documented its use against a journalist and an activist. Its reappearance in newly obfuscated form indicates continued investment in domestic surveillance capability rather than a one-off procurement.
Pegasus has been documented against journalists, dissidents, and officials in dozens of countries since Citizen Lab and Amnesty first exposed its commercial spyware ecosystem in 2016 and 2021. Despite the 2021 US blacklisting of NSO Group and repeated European Parliament inquiries into spyware abuse within the EU and candidate states, the company has continued operating, reportedly restructuring corporate ownership to sustain sales relationships.
Analysis & Assessment
The target selection, an MP, a local official, and student organizers rather than foreign intelligence targets, indicates the tasking priority was domestic political containment, not counterterrorism or counterespionage, the justifications typically offered for lawful-intercept spyware use. This pattern is consistent with prior mercenary-spyware abuses documented against civil society in Hungary, Poland, Greece, and Spain, suggesting Serbia's case is unlikely to be an isolated anomaly within the wider European pattern.
Serbia's EU accession process, already strained by rule-of-law concerns in successive European Commission progress reports, will likely face renewed scrutiny from the European Parliament and digital rights bodies. Brussels has limited enforcement leverage over candidate-country surveillance practices short of freezing accession benchmarks, an outcome Belgrade has weathered before without altering security-service conduct.
Absent independent attribution of the operator, Belgrade's denial notwithstanding, expect continued forensic disclosures from Citizen Lab, Amnesty, and SHARE Foundation as further Apple threat notifications prompt device analysis among Serbian civil society. The persistence of NoviSpy alongside commercial Pegasus licensing suggests Serbian security services are running a dual-track approach: proprietary tools for sustained domestic operations, commercial spyware for opportunistic or higher-value targeting.
