At least 14 individuals from Serbia’s civil society have been identified as targets of advanced spyware in the months leading up to local elections in March, according to the SHARE Foundation, a digital rights organization based in Serbia. The foundation revealed this information on Wednesday, citing forensic evidence uncovered during its investigation into cyber threats targeting activists and opposition figures. The alleged attacks were first detected in August after Apple alerted users in 110 countries they might have been victims of commercial spyware. This marks the largest documented case of such surveillance in Serbia to date, according to the foundation's statement. The incidents highlight the use of powerful and invasive spyware aimed at students and members of the political opposition ahead of contentious elections. Among the confirmed targets were members of student movements, activists, opposition MPs, and one local council member. At least one device was infected with Pegasus, a spyware developed by the Israeli company NSO Group, while at least two devices were attacked using malicious software similar to NoviSpy, which Amnesty International first discovered in Serbia in December 2024. Reuters could not determine who was behind the alleged attacks. NSO previously stated that its products are sold exclusively to governments. Neither the Serbian government nor NSO Group responded immediately to requests for comment. In a January report, NSO Group indicated it would cooperate with clients to resolve potential rule violations. “In cases of serious or repeated non-compliance with rules, NSO may suspend or terminate cooperation,” the company stated. One device linked to a member of a student movement was targeted by a zero-click version of Pegasus, meaning the spyware was installed without requiring any action from the user. NoviSpy was found on the phone of a student movement member whose device had previously been seized during a police investigation, according to SHARE. The attacks coincided with local elections held on March 29 in ten municipalities. According to SHARE, these elections were considered a test of the ability of opposition political groups supported by students to organize and challenge politicians from the ruling party. The organization warned that digital attacks could signal similar activities ahead of parliamentary elections scheduled for November. “New forensic findings show that Serbian student activists remain targets of invasive spyware,” said Donncha Ó Cearbhaill, head of the security laboratory at Amnesty International, who participated in the investigation of the attacks. Pegasus was installed on the phone of at least one student between December 2025 and January 2026, according to Bill Marczak, a senior researcher at Citizen Lab, a Canadian organization monitoring digital threats and investigating these cases. He added that Apple’s recent security updates have neutralized the spyware. John Scott-Railton, another senior researcher at Citizen Lab, noted that the findings from his organization and Apple’s warnings “reveal that the peaceful pro-democratic movement in Serbia has been aggressively targeted by commercial spyware ahead of key election cycles in 2026.” The U.S. government placed NSO on a blacklist in 2021 due to concerns over human rights abuses. In 2025, the company was acquired by an American investment group, although it continues to operate from Israel and is subject to Israeli regulations. Apple stated in a press release that it sent alerts about threats to users in 110 countries on August 13 and added that it has already sent such warnings to users in more than 150 countries.
★
Neka vijesti ostanu poštene.
ObjectiveNews financiraju čitatelji i bez oglasa je – pristranost vam pokazujemo, ne skrivamo. Podržite neovisno novinarstvo za 4 €/mjesec.
Postani podupiratelj