Fourteen phones confirmed infected, a state security agency calling it sensationalism, and a server link researchers documented back in 2024 that the denial never once addresses: this is not the sound of a rebuttal that can withstand scrutiny. This week's technique is running the same free forensic check Amnesty's Security Lab used to confirm this week's infections. Serbia's spyware wave is the proof, because the government's rebuttal never touches the one artefact the case turns on.
|
Intercept
Citizen Lab and Amnesty International confirmed Pegasus and a new NoviSpy build on Serbian devices this week, the latest entry in a campaign SHARE Foundation has now documented against fourteen people, with eleven more phones under analysis. At what point did the open record already show this campaign was active?
|
|
Signal
Amnesty's own Security Lab built the free tool that confirmed these infections, and most practitioners have never run it. Here is how to read the output.
|
|
Shadow
Serbia's state security agency called the findings trivial. It has not addressed the fact that this same spyware was already tied to its own servers in 2024. Here is how to document that gap.
|
| 01 |
Section 01 of 03 · Intercept
Fourteen Serbian phones were confirmed infected with mercenary spyware since January
|
|
The SHARE Foundation, a Belgrade-based digital rights organisation, reported on 2 September that at least fourteen people connected to Serbia's student protest movement and opposition politics have been targeted with commercial and custom spyware since the start of 2026, including a sitting member of parliament and a local councillor. The Citizen Lab at the University of Toronto independently confirmed that a student activist's iPhone was infected with NSO Group's Pegasus spyware via an iMessage zero-click exploit, with high-confidence indicators spanning December 2025 to January 2026. Amnesty International's Security Lab separately confirmed two Android devices carrying a newly built variant of NoviSpy, spyware first documented in Serbia in 2024.
| PEGASUS CONFIRMED |
iPhone, iMessage zero-click exploit, Dec 2025 to Jan 2026 (Citizen Lab) |
| NOVISPY, NEW BUILD |
2 Android devices, installed via physical access (Amnesty Security Lab) |
| DOCUMENTED TARGETS |
14 since January 2026, incl. 1 MP, 1 local councillor (SHARE Foundation) |
| Eleven more flagged phones remain under analysis, so 14 is a floor, not a ceiling. |
The open record already carried the preconditions. Apple sent threat notifications to twelve people in Serbia on 13 August, warning them of suspected state-sponsored spyware targeting. Citizen Lab's own guidance treats an Apple threat notification as a high-confidence indicator that a device should be presumed infected, not investigated at leisure. Twelve people in Serbia received exactly that warning under three weeks before SHARE's forensic confirmation reached the public.
The practitioner question is at what point the open record contained sufficient signal to flag this campaign, and the answer is 13 August, not 2 September. An Apple threat notification is not a hint that a device might be worth checking eventually. It is a presumed-infected classification from the company best positioned to know, and it should trigger forensic triage the same day it arrives.
|
Do this now
If you or a source gets an Apple or Google threat notification, treat the device as compromised immediately. Do not factory reset it. Preserve an unencrypted backup first, before anything else, since that backup is the only thing a forensic check can examine.
|
Cellebrite, the Israeli firm whose forensic tools enabled the 2024 NoviSpy infections, halted sales to Serbia after Amnesty's report exposed that pattern. The 2026 wave shows what that cutoff actually achieved: Serbia did not stop, it built its own detection-evading variant. A vendor sanction changes which tool a state uses. It does not change whether the state keeps using one.