Back to all lessons
Awareness Lessons
last month

Pegasus & NoviSpy Spyware Target Serbian Activists via Zero-Click Exploits

Serbian activists, a member of parliament, and a local official were targeted by two sophisticated spyware strains — Pegasus and a new NoviSpy variant — in what researchers describe as the largest wave of spyware surveillance in Serbia to date. The Pegasus infection exploited a zero-click vulnerability, meaning victims needed no interaction whatsoever for their devices to be compromised, highlighting how traditional security awareness training alone cannot protect against state-level threats. Evidence points to Serbian authorities as potential operators of the NoviSpy campaign, raising serious concerns about government misuse of surveillance tools against civil society, particularly ahead of elections. This case underscores that high-risk individuals such as journalists, activists, and politicians require specialized, hardened device configurations and proactive threat hunting beyond standard consumer security practices.

Tactical Insight

Immediate actions

  • Enroll high-risk individuals (activists, journalists, officials) in Apple Lockdown Mode or equivalent Android hardening profiles immediately.
  • Audit and update all mobile devices to the latest OS and security patch versions to close known zero-click exploit vectors.
  • Conduct forensic sweeps of devices belonging to at-risk individuals using tools such as Amnesty International's Mobile Verification Toolkit (MVT).

Long-term improvements

  • Establish a dedicated device security program for civil society organizations, providing regularly refreshed, hardened devices to high-risk personnel.
  • Implement a mobile threat defense (MTD) solution to continuously monitor device integrity and detect anomalous network traffic indicative of spyware beaconing.
  • Develop and rehearse an incident response plan specifically for spyware compromise scenarios, including device isolation, forensic preservation, and legal notification procedures.

Detection measures

  • Monitor for indicators of compromise (IoCs) associated with known commercial spyware vendors and subscribe to threat intelligence feeds from organizations like Citizen Lab and Amnesty Tech.
  • Regularly review device network traffic logs for unexpected outbound connections to known spyware command-and-control infrastructure.
  • Perform periodic third-party security audits of devices used by high-risk personnel to identify stealthy persistence mechanisms.