$ techbeacon▋
CVE & Exploits

Serbian Student Activist’s iPhone Compromised by Pegasus Spyware via iMessage Zero‑Click Attack

Serbian Student Activist’s iPhone Compromised by Pegasus Spyware via iMessage Zero‑Click Attack

A Serbian university student involved in political activism discovered that his iPhone had been infected with the Pegasus surveillance software after receiving a seemingly ordinary iMessage, according to a report from Infosecurity Magazine.

The intrusion did not require the recipient to click any link or download a file; instead, the exploit leveraged a zero‑click vulnerability in Apple’s iMessage service, allowing the spyware to install itself silently. Once installed, Pegasus can grant attackers full access to the device’s microphone, camera, messages, and location data.

While Pegasus has been linked to a range of high‑profile targets worldwide—including journalists, human‑rights defenders, and government officials—the case highlights how the tool is also being deployed against younger, grassroots activists. The Serbian student, who requested anonymity for safety reasons, reported unusual battery drain and unexpected network activity before consulting a security specialist who identified the Pegasus signature.

Apple has historically patched many of the vulnerabilities that Pegasus exploits, but the spyware’s developers, reportedly the Israeli firm NSO Group, have continually adapted to new defenses. Zero‑click attacks are especially concerning because they bypass user interaction entirely, making detection difficult until forensic analysis is performed.

The incident arrives amid growing scrutiny of Pegasus by European regulators and human‑rights organizations, which have called for stricter oversight of the technology’s export and use. Serbia’s government has not commented publicly, but the episode may prompt local authorities to examine how foreign surveillance tools are reaching activists within the country.

Cybersecurity experts advise users to keep devices updated, enable two‑factor authentication, and consider additional security layers such as encrypted messaging apps. For high‑risk individuals, regular device audits by independent security firms are increasingly recommended to detect hidden malware like Pegasus before it can compromise sensitive communications.

Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related