News

SHARE Foundation: Students and Opposition Politicians Targeted by Spyware

The SHARE Foundation has confirmed that at least 14 people in Serbia were targeted with advanced spyware since at the beginning of 2026 – the largest documented wave of such surveillance in the country to date. Those targeted include members of the student movement, activists, a member of parliament, and a local councilor, all from opposition parties. The timing coincides with the local elections held on March 29, 2026. 

Spyware of this kind can access everything on a device – messages, contacts, photos, app data, and other files – and can secretly record the screen or activate the microphone and camera. Its use is illegal in Serbia. 

What happened?

This past August, twelve people contacted our digital forensics experts after receiving a warning on their phones that they had been targeted in a spyware attack. Apple issues these warnings with high confidence when a user has been targeted by mercenary spyware. SHARE Foundation’s forensic analysis later confirmed two more infections – with a new version of NoviSpy, spyware first discovered in Serbia in 2024.

Two global digital forensics labs – Citizen Lab at the University of Toronto and Amnesty International’s Security Lab – independently confirmed SHARE Foundation’s findings.

Citizen Lab investigators confirmed that the phone belonging to the student movement member who received the warning was infected with Pegasus, spyware developed by the Israeli company NSO Group. The device was hacked with a 0-click exploit targeting iPhone application iMessage. This means that the device was infected remotely, without any knowledge or interaction by the user. 

“We confirmed that the student’s device was hacked with a Pegasus zero-click exploit across December 2025-Jan 2026.” – Bill Marczak, Senior Researcher at The Citizen Lab.

Furthermore, the remaining 11 devices received Apple Threat Notifications, a high-confidence indicator that they had been targeted with mercenary spyware and should therefore be treated as presumed infected.

“Our forensic findings, and this fresh wave of Apple Threat Notifications reveal that Serbia’s peaceful pro-democracy movement is being aggressively targeted with mercenary spyware ahead of key 2026 election cycles” – John Scott-Railton, Senior Researcher at The Citizen Lab.

Amnesty International confirmed the Infection with the new version of NoviSpy spyware on the phone of a student movement member whose phone had previously been confiscated when he was brought in for police questioning. 

“The forensic findings by SHARE prove that Serbian students continue to be targeted with invasive Android spyware tools, installed while detained by Serbian authorities. The latest 2026 case also reveals a new Android spyware, similar in functionality to NoviSpy, but newly built with specific efforts taken to avoid detection by security experts.”  – Donncha Ó Cearbhaill, Head of Amnesty International’s Security Lab

The same spyware was detected on another device, after private Viber messages from that phone were disclosed live on TV Informer. 

Further forensic analysis is ongoing, with support from digital forensics experts at Citizen Lab and Amnesty International. 

A gross abuse of technology

Intrusive spyware varies by infection method and level of technical sophistication. Pegasus is military-grade spyware, sold exclusively to states and state agencies. It can be installed remotely, with no interaction from the user required, and its key components – the control interface and the servers storing collected data – are typically based in the client country, at the agency’s own premises or headquarters. By contrast, installing the newly discovered spyware requires physical access to the device.

The use of such intrusive technologies represents a gross violation of the right to privacy and heightens the “chilling effect” among citizens, which directly affects related rights such as freedom of expression and movement, as well as a broader range of political freedoms. 

The targeting of students, an MP, and a local councilor is especially troubling: political espionage strikes directly at the equality of political actors and the integrity of the electoral process. Democracy depends on elected representatives being free to communicate, organize, and hold those in power to account – without fear of secret, unlawful surveillance. If even they aren’t protected from such attacks, citizens can hardly expect their own privacy and political freedoms to be respected. Practices like this erode trust in institutions, and in the very possibility of free political action. 

By its function and purpose, spyware qualifies as a computer virus – that is, a program or set of commands that acts on other programs or data within a computer or network – and introducing it constitutes a criminal offense under Serbia’s Criminal Code. Using spyware means gaining unauthorized access to everything on a device – deliberately causing harm not only to the targeted person, but to everyone else whose data happens to be stored on that device. 

In late 2024, Amnesty International published a report on the forensic analysis of infected devices belonging to users in Serbia – an analysis the SHARE Foundation also took part in. A previously unknown piece of spyware was uncovered, which researchers named NoviSpy, configured to send data stolen from phones to a server whose IP address belongs to Serbia’s Security Information Agency (BIA). It was also found that the spyware had been installed on devices – confiscated during police interviews with targeted journalists, activists, and civil society members – by misusing Cellebrite, a digital forensics tool Serbia’s Ministry of Interior received as a donation from Norway. Criminal complaints filed in these cases are still pending in court.

The upcoming elections further heighten an already tense political climate, amid growing physical and digital repression of political dissent, including students, journalists, and activists. This digital dimension builds on existing tactics of intimidation, arrest, and detention on baseless charges. 

What can citizens do to protect themselves?

Apple (iOS) and Google (Android) periodically notify users if their device has been targeted by spyware. If you receive such a notification, contact a trusted expert organization without delay – they can help you collect and analyze the relevant data.

Beyond the general advice to keep devices and apps updated and avoid content from unknown sources and suspicious links, citizens at higher risk – students, activists, journalists, and opposition politicians – are advised to enable advanced security features on their devices (Lockdown Mode for iOS, Advanced Protection for newer Android devices).

Related content

MUP and BIA illegally hacking phones of activists and journalists

Proven use of spyware and forensic tools contrary to law The use of spyware represents a serious attack on human rights, freedom of expression and privacy of citizens. In Serbia its use is becoming a common practice. A new report by Amnesty International indicates widespread use of spyware against activists, journalists and members of civil society by […]

BIRN Serbia journalists targeted with spyware

According to the findings by Amnesty International (AI), two investigative journalists of the online portal BIRN Serbia have been targeted by the Pegasus spyware, developed by the Israeli NSO Group. Jelena Veljković and another journalist who wished to remain anonymous received suspicious Viber messages on 14 February from the same unknown Serbian phone number. One […]

Spyware attack attempts on mobile devices of members of civil society discovered

SHARE Foundation warns of the disastrous impact of misuse of technology against the critical public in Serbia On October 30, two members of civil society from Belgrade received an alert from Apple that they were potential targets of state-sponsored technical attacks. Thanks to good cooperation with civil society organisations in Serbia, they contacted the SHARE […]