Serbia’s Spyware Abuse Escalates as Students Targeted in Election Run-Up

Forensic investigations have uncovered Serbia’s largest documented wave of spyware targeting, with student activists and opposition figures among the victims ahead of a high-stakes election – the latest example of the authorities’ hostile use of surveillance technology.
As Serbia heads towards a snap parliamentary election, members of the country’s student-led protest movement and opposition politicians challenging the government of President Aleksandar Vucic have been targeted with some of the world’s most intrusive surveillance tools.
At least 14 people have beentargetedwith sophisticated spyware since the beginning of 2026, according to the Belgrade-based digital rights organisation SHARE Foundation, which described the cases as the largest documented wave of spyware targeting in Serbia to date. The targeting happened around tightly-contested local elections in March, and those affected included student activists, an opposition MP and a local councillor.
The investigation began after 12 people contacted SHARE in August after receiving Apple notifications warnings that they had been targeted with mercenary spyware. Less than two years after the Serbian authorities’ use ofdomestically-developed spyware NoviSpywas exposed, SHARE researchers in collaboration with theCitizen Laband Amnesty International found a newly engineered version on students’ phones, alongside the first confirmed successful infection of a member of Serbia’s student protest movement byPegasus spyware.
Investigatorsfoundevidence of a zero-click iMessage attack dating from December 2025 and January 2026, pointing to the highly intrusive Pegasus malware produced by Israel’s NSO Group. Such an infection can give an attacker access to messages, photographs and other data, as well as the ability to activate a phone’s microphone and camera covertly.
Source: balkaninsight.com



