- The Mess: Citizen Lab has confirmed that an iPhone belonging to a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware through an iMessage zero-click exploit. The victim did nothing to trigger the attack.
- The Damage: A successful Pegasus infection can give an attacker broad access to the phone, including private messages, photos, notes, encrypted communications, microphone and camera.
- The Fix: Update iPhones immediately, enable Lockdown Mode if you are at elevated risk, and treat an Apple Threat Notification as a serious compromise requiring forensic investigation.
You don’t need to click anything.
You don’t need to open a suspicious attachment.
You don’t even need to know an attack is happening.
That’s the ugly part of a zero-click exploit.
Citizen Lab, working with the SHARE Foundation, has confirmed that an iPhone belonging to a member of Serbia’s student protest movement was infected with Pegasus, the commercial spyware developed by NSO Group. The forensic evidence shows that the attacker used a zero-click exploit targeting Apple’s iMessage application.
The infection occurred sometime between December 2025 and January 2026. The exact date has not been disclosed because the victim asked to remain anonymous. Citizen Lab says the forensic evidence provides high-confidence indicators of Pegasus infection.
The victim did not have to interact with the malicious content.
That’s what separates zero-click attacks from the usual phishing story.
There was no fake login page.
No “urgent security alert”.
No malicious link waiting for a careless tap.
The exploit was delivered through iMessage and executed without the target knowingly doing anything.
Citizen Lab believes Apple subsequently eliminated the vulnerability with iOS 18.4.1. That update was released in April 2025, meaning the particular exploit chain used in this case should no longer work against properly updated devices.
But the incident demonstrates why patching alone is not enough for people who are specifically targeted.
Pegasus is not ordinary stalkerware.
Once successfully installed, it can provide extensive access to the device. Citizen Lab says the spyware can access private data, notes, pictures and even encrypted messages. It can also covertly activate the microphone and camera.
And Serbia appears to be experiencing something larger than one isolated infection.
The SHARE Foundation has documented at least 14 cases involving members of Serbia’s student movement and civil society, as well as an opposition member of parliament, who received Apple Threat Notifications indicating possible targeting with mercenary spyware.
Only one of those cases has so far been publicly confirmed by Citizen Lab as an actual Pegasus infection.
That distinction matters.
An Apple Threat Notification is a high-confidence warning that a device has been targeted by sophisticated mercenary spyware. It is not automatically proof that Pegasus successfully infected the device.
In this case, however, investigators had forensic evidence.
That’s a much stronger signal.
Citizen Lab also says that the newly confirmed Pegasus case is part of a longer history of spyware abuse in Serbia, where civil-society members have previously been targeted with Pegasus and domestic surveillance tools such as NoviSpy.
The timing makes the story even more uncomfortable.
The targets are connected to Serbia’s student-led protest movement and civil society, while the country is heading toward another important election cycle.
That does not prove who ordered the Pegasus operation.
Citizen Lab’s findings establish that Pegasus was used to compromise the phone. They do not by themselves identify the specific NSO customer responsible for the attack. That distinction is important when discussing attribution.
The technology itself is the bigger problem.
Commercial spyware companies sell governments and other customers tools capable of exploiting vulnerabilities in mainstream mobile operating systems. When those tools rely on zero-click vulnerabilities, the traditional security advice of “don’t click suspicious links” becomes almost useless.
There is nothing for the victim to click.
This is why Apple Threat Notifications matter.
Apple sends these alerts when it detects activity consistent with highly sophisticated mercenary spyware targeting a particular customer. Citizen Lab recommends treating such a notification as an indication of presumed infection and seeking expert assistance.
For users who believe they may be specifically targeted, Citizen Lab also recommends Apple’s Lockdown Mode.
It is deliberately restrictive. Some features and conveniences are sacrificed to reduce the attack surface available to sophisticated spyware. For an ordinary user, that trade-off may be unnecessary.
For a journalist, activist, researcher, politician or other high-risk target, it can make considerably more sense.
The most important defensive measure remains painfully boring:
Keep the device updated.
The specific iMessage exploit identified in this investigation is believed to have been rendered ineffective by Apple’s security updates.
But the larger lesson is harder to patch.
A fully invisible mobile attack does not need social engineering.
It needs one exploitable parser, messaging component or system service — and an attacker willing to spend the money required to weaponize it.
Bugstoday’s take: “Don’t click suspicious links” is great advice until the attacker doesn’t need you to click anything. Pegasus continues to demonstrate why zero-click exploitation remains one of the nastiest capabilities in mobile security. If you’re a high-value target, assume that your iPhone is not magically immune because it is an iPhone. Patch it, use Lockdown Mode when appropriate, and take Apple’s threat notifications seriously.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
- Citizen Lab — Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist
- SHARE Foundation — Students and Opposition Politicians Targeted by Spyware
- Apple — iOS 18.4.1 Security Content
- Amnesty International Security Lab — Pegasus research




