$ techbeacon▋
CVE & Exploits

Serbian Student Activists Hit by First Confirmed Pegasus Spyware Case of 2026

Serbian Student Activists Hit by First Confirmed Pegasus Spyware Case of 2026

Security researchers have identified the first verified infection of the Pegasus surveillance tool in 2026, along with a related spyware variant, on the mobile devices of Serbian student activists and other dissenting figures. The discovery marks what analysts describe as the most extensive documented wave of such monitoring in the country to date.

The investigation, conducted by an independent cybersecurity team, revealed that the Pegasus payload—originally developed by the Israeli firm NSO Group—had been deployed against a network of activists involved in university protests and civil‑society initiatives. In parallel, a lesser‑known offshoot of the software, dubbed "NoviSpy," was also found on several devices, suggesting a coordinated effort to broaden the scope of surveillance.

Pegasus has been at the center of international controversy for years, with multiple governments and human‑rights groups accusing the tool of enabling illicit spying on journalists, opposition politicians, and activists worldwide. While previous incidents have been reported across Europe and the Middle East, this is the first time the spyware has been conclusively linked to a Serbian target pool in the current year, underscoring a shift in its geographic focus.

Local NGOs and digital‑rights advocates have expressed alarm over the findings, warning that the intrusion threatens the safety of individuals exercising their constitutional freedoms of expression and assembly. The activists affected report that the malware could grant attackers access to messages, location data, and microphone feeds, potentially exposing protest plans and personal contacts. Calls for a transparent investigation have been amplified by the European Union, which has urged Serbia to adhere to democratic standards and protect the digital rights of its citizens.

Authorities in Belgrade have not yet commented on the technical report, but the revelation is likely to intensify scrutiny of the government's cybersecurity policies and its relationships with foreign surveillance vendors. Experts suggest that the incident could prompt legislative reforms, increased oversight of digital tools, and broader cooperation with international watchdogs to mitigate the risk of future incursions. As the investigation proceeds, the case may become a benchmark for how emerging democracies confront sophisticated spyware threats.

Source: CyberScoop
Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related