$ techbeacon▋
CVE & Exploits

Serbian Student Protester’s iPhone Compromised by Pegasus Spyware via Zero‑Click iMessage Attack

Serbian Student Protester’s iPhone Compromised by Pegasus Spyware via Zero‑Click iMessage Attack

A forensic investigation by the Citizen Lab, in partnership with the SHARE Foundation, has uncovered that the iPhone of a participant in Serbia’s ongoing student protest movement was infected with NSO Group’s Pegasus spyware. The intrusion was carried out using a so‑called zero‑click exploit that leverages a vulnerability in Apple’s iMessage service, allowing the malicious code to be installed without any interaction from the device owner.

The analysis, first reported by The Hacker News, confirms that the exploit was executed remotely, bypassing traditional security prompts that would normally alert a user to an incoming attachment or link. By exploiting the iMessage flaw, the attackers were able to gain full access to the phone’s data, including messages, location information, and potentially the device’s microphone and camera.

Pegasus, a surveillance tool developed by Israeli firm NSO Group, has been linked to a range of high‑profile espionage operations worldwide. It is typically sold to government agencies for use against criminal networks and terrorism suspects, but numerous investigations have revealed its deployment against journalists, activists, and opposition figures in a variety of jurisdictions. The latest case adds Serbia to a growing list of countries where the spyware appears to have been used to monitor dissent.

Serbia’s student movement has been at the forefront of nationwide demonstrations demanding reforms in the higher‑education system, increased funding, and greater academic freedom. The protests have drawn significant public attention and have occasionally clashed with authorities. While the precise motive behind the targeting of the student activist’s phone remains unclear, the incident underscores the heightened surveillance risks faced by civil‑society participants in the digital age.

Citizen Lab’s technical team traced the malicious code to a known Pegasus payload that leverages the iMessage zero‑click vulnerability first disclosed in 2021. The researchers noted that the exploit does not require the victim to open a message or click a link, making it especially insidious. Apple has since released patches addressing the underlying flaw, but the presence of the spyware on the device suggests the infection occurred before the relevant update was applied.

Both the Citizen Lab and the SHARE Foundation have called for a transparent investigation into how the spyware was deployed and who authorized its use. They emphasize the need for stronger legal safeguards to protect activists and students from unwarranted digital intrusion. International human‑rights organizations have previously urged governments to impose stricter export controls on surveillance technology like Pegasus, citing the tool’s potential for abuse.

Serbian authorities have not yet commented on the findings, and it is unclear whether any legal action will be taken against the parties responsible for the intrusion. The incident, however, highlights the broader challenge of securing mobile devices against sophisticated state‑level cyber‑espionage tools, particularly in environments where political dissent is prevalent.

As the investigation continues, experts advise users of vulnerable devices to install the latest software updates promptly and to consider additional security measures such as encrypted messaging apps. The case serves as a stark reminder that even seemingly routine communications can become a gateway for advanced surveillance platforms.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related