Threat Intelligence

Pegasus Spyware Used to Target Serbian Student Activist via Zero-Click iPhone Exploit

The Hacker News · 3 Sept 2026
Key Takeaway Keep mobile devices and apps fully updated and consider mobile threat detection tools if your business handles sensitive or high-risk communications.

Security researchers at Citizen Lab, working with Serbia's SHARE Foundation, have confirmed that an iPhone belonging to a member of Serbia's student protest movement was infected with Pegasus spyware developed by NSO Group. The infection was delivered through a zero-click exploit sent via iMessage, meaning the target did not need to click a link or take any action for the malicious code to run and take control of the device.

Pegasus is one of the most sophisticated commercial spyware tools known, capable of accessing messages, calls, photos, location data, and microphone or camera feeds without the victim's knowledge. Because zero-click exploits require no interaction, they are extremely difficult to detect or prevent through user awareness alone, and they often target activists, journalists, and political figures rather than typical businesses.

While this case involves a high-profile activist rather than a small business, it highlights how advanced spyware capabilities continue to evolve and occasionally surface in commercial or leaked forms. Businesses handling sensitive client data, legal matters, or political-adjacent work should be aware that mobile devices can be compromised silently, and should keep devices updated and monitor for unusual battery drain, data usage, or performance issues as potential warning signs.

Pegasus spyware mobile security zero-click exploit NSO Group

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.