Serbian Student Activist Infection (2025-2026)
Citizen Lab confirmed a Pegasus infection of a Serbian student activist with high-confidence evidence across December 2025 to January 2026, assessing an iMessage zero-click vector was used. The vulnerability was patched as of iOS 18.4.1.
- 01Evidence status: FORENSICALLY CONFIRMED
- 02Attack vector: iMessage zero-click
- 03Spyware: Pegasus
- 04Researcher: Citizen Lab
What Happened
Citizen Lab confirmed a Pegasus infection of a Serbian student activist with high-confidence evidence across December 2025 to January 2026, assessing an iMessage zero-click vector was used. The vulnerability was patched as of iOS 18.4.1.
Evidence
Evidence status: FORENSICALLY CONFIRMED
Attack vector: iMessage zero-click
“Serbian Student Activist Infection (2025-2026) involved Pegasus.”
Researcher: Citizen Lab. Primary source: CL-2026-09-02.
Attribution
NOT ATTRIBUTED: Citizen Lab confirmed infection but did not publicly identify the operator.
What NSO Group Says
NSO Group has stated its technology is licensed to vetted governmental agencies for legitimate law-enforcement and national-security purposes. NSO has not typically commented on individual cases or operators.
Legal Status
Investigation ongoing; SHARE Foundation and Citizen Lab reported at least 14 notified civil-society/student/opposition figures.
