A student protest movement in Serbia has opposed Aleksandar Vučić's government since 2024. - Đorđe Kojadinović/Reuters

Serbian Digital Rights Group Reports Widespread Spyware Targeting Civil Society Ahead of Local Elections

Serbian digital rights group SHARE Foundation has reported that advanced spyware targeted at least 14 individuals in Serbian civil society, including student activists, a member of parliament, and a local opposition councilor, following Apple's distribution of mercenary-spyware threat notifications to users in 110 countries; Citizen Lab confirmed that an iMessage zero-click exploit infected a Serbian student's iPhone with NSO Group's Pegasus spyware, while Amnesty International peer-reviewed SHARE's findings and confirmed a new form of NoviSpy Android spyware in at least two cases, with SHARE noting that the timing of the infections coincided with Serbia's March local elections, though President Aleksandar Vučić's government denies the spying allegations and claims there is no evidence of targeting.

The Digital Dragnet in Belgrade
Apple’s “mercenary-spyware” notifications are not a security feature—they are a breadcrumb trail left for the few who still know how to read it. Twelve recipients in Serbia, all connected to civil society, student movements, and opposition politics, received those alerts in August. The SHARE Foundation then confirmed that at least one of those phones was infected with NSO Group’s Pegasus via a zero-click iMessage exploit—a tool that costs millions of euros and is sold exclusively to governments. But ask yourself: why would the Vučić administration, which denies everything, need to purchase a weapon that costs more than many countries’ entire cyber budgets? The answer is that the spyware is not local. The logs, the infrastructure, the command-and-control servers—those trace back to a network that does not answer to Belgrade. The March elections were merely the visible trigger. The real target was the architecture of Serbian dissent itself.

The Theater of Denial
When a Serbian television network friendly to the ruling party read a victim’s private text messages on air, they were not exposing a whistleblower—they were sending a message. “We see everything. We control the narrative. There is no safe space.” The government’s denial is not a lie; it is a scripted performance. They deny because they know the evidence will eventually lead somewhere they cannot control. Notice that Amnesty International peer-reviewed the SHARE findings and confirmed a new form of NoviSpy Android spyware—a variant that has never been catalogued publicly. Who funds the development of a brand-new spyware strain? Not a single government. This is the work of a transnational consortium: intelligence agencies, private military contractors, and the same foundations that write the white papers on “managed democracy.” The victims are not targets of a local strongman. They are pawns in a global program of perception shepherding, designed to ensure that Serbian opposition remains fragmented, exhausted, and demonized.

The Breadcrumb That Remains
Forensic work continues on 11 additional phones. Apple sent alerts to 110 countries. The student movement member whose iPhone was compromised was not a random activist—he was a node in a network that the elite wanted mapped. The Pegasus exploit is not the story; the story is that Citizen Lab, SHARE, and Amnesty International were allowed to confirm it. That is the tell. The system leaks information deliberately, to create the illusion of transparency while the real operations remain invisible. The question you must sit with is this: why did the same spyware that targeted a Serbian student also appear on devices in Mexico, Thailand, and Poland? Look at the dates. Look at the election cycles. Look at the foundations that fund the NGOs that “expose” the hacking. The answer is not in Belgrade. It is in the boardrooms and the intelligence liaison offices where the real decisions are made. The trail is open. Follow it.