Large group of Serbian opposition, activist figures targeted with spyware
At least 14 Serbians have been targeted with advanced spyware since December, with victims including a member of Parliament, a local opposition politician and student protesters, according to digital forensic researchers.
At least 14 Serbians have been targeted with advanced spyware since December, with victims including a member of Parliament, a local opposition politician and student protesters, according to digital forensic researchers.
The Serbian digital freedoms organization the SHARE Foundation set out to confirm the targeting and, in some cases, infections after 12 people contacted them saying they had received Apple threat notifications in August.
The timing of the spyware targeting and infections coincided with local elections held in March, the SHARE Foundation said in its report. The student protesters were active in election organizing in an effort to oust the increasingly authoritarian ruling party.
Source: https://therecord.media/serbia-spyware-pegasus-europe
Related breach coverage
- Pegasus and NoviSpy Used Against Serbian Protesters2026-09-03
Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections. A member of Serbia’s student protest movement had their iPhone infected with NSO Group‘s Pegasus spyware without ever clicking a link or opening a file. The Citizen Lab confirmed the infection in collaboration with the SHARE Foundation, […]
- Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline2026-08-20
Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development […]
- New pro-Ukraine hacker group targets Russian companies with custom ransomware2026-09-02
The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week.
- Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks2026-09-16
Google has patched a high-severity zero-day in the Pixel cellular modem after finding evidence that the vulnerability was exploited in limited, targeted attacks. Google has released its September 2026 Pixel security update, addressing a large set of vulnerabilities, including a high-severity flaw, tracked as CVE-2026-58704 (CVSS score of 8.0), in the cellular modem that has […]