No tap, no file, no link: that is all it took for a commercial spyware implant to take root on the iPhone of a Serbian student protest organizer, where it listened for months before anyone looked. Citizen Lab, examining the handset alongside Belgrade’s SHARE Foundation, matched the infection to NSO Group’s Pegasus, entered through an iMessage hole that needed no action from the owner. Apple closed that hole in iOS 18.4.1, released back in April 2025.
High-confidence signs date the compromise to December 2025 through January 2026, and examiners will not exclude further episodes. SHARE has counted fourteen people targeted by advanced spyware since the start of 2026, among them student organizers, civil society activists, an opposition member of parliament and a local councilor. Twelve came forward in August after receiving Apple threat notifications, and eleven devices remain presumed infected pending deeper forensic work. Local polls on March 29 and early parliamentary elections expected in October bracket the timeline.
Android users face a parallel threat. Amnesty International’s Security Lab studied a phone confiscated from another student during police questioning and uncovered a surveillance program resembling the local NoviSpy tool but rebuilt to escape detection. The same strain later showed up on a second device after private Viber messages from it aired on pro-government television.
Citizen Lab’s guidance for anyone who sees Apple’s warning on a lock screen: assume the device is compromised and bring in specialists without delay. High-risk users should stay current on iOS and enable Lockdown Mode, which blocks entire classes of silent remote attacks.