Citizen Lab and Amnesty International confirmed Pegasus and a new NoviSpy variant on 14 Serbian targets, including activists, a member of parliament, and a local official, in what the SHARE Foundation called the country’s largest documented spyware wave so far. The infections landed around the run-up to local and parliamentary elections, and at least some victims were notified by Apple alerts.
One of the NoviSpy cases appears to have begun after police took a student’s phone during questioning; another followed disclosure of private messages from the device. That matters because spyware like Pegasus and NoviSpy can read messages, watch screens, and turn on the microphone, so the compromise can start while the target is already in custody or otherwise out of control of the device.
For organizations that work with activists, students, journalists, or officials, the exposure is not just remote targeting but physical seizure and state pressure. The reporting points to a political-surveillance campaign, and the detention-linked infection path means normal phishing-focused mobile defenses do not describe the whole threat picture.