Serbian Students Targeted With Israeli Spyware Ahead Of Elections (Worthy News Investigation)
by Stefan J. Bos, Worthy News Europe Bureau Chief
BELGRADE/BUDAPEST (Worthy News) – More than a dozen members of Serbia’s influential student movement and opposition figures were targeted with sophisticated spyware ahead of parliamentary elections, according to investigators, fueling concerns about government surveillance in what researchers call the country’s largest documented wave of such spying.
The surveillance software can secretly penetrate smartphones, giving operators access to private messages and other data and potentially allowing them to activate cameras and microphones without the owner’s knowledge.
At least 14 people have been targeted since the beginning of the year, according to Serbia’s SHARE Foundation, a digital rights group investigating the cases.
In one confirmed case, researchers at the University of Toronto’s Citizen Lab found that student activist Jelena Kontić’s iPhone had been remotely infected with Pegasus, powerful spyware developed by Israeli company NSO Group.
The infection was carried out through a “zero-click exploit” targeting Apple’s iMessage service, meaning Kontić did not have to click a link or take any other action for the spyware to enter her phone.
PEGASUS INFECTS STUDENT ACTIVIST
Kontić, who is active in the student movement’s “Student in Every Village” campaign, expressed anger that the surveillance potentially compromised everyone with whom she communicated.
“It looks as if your phone is in their hands,” she stressed, explaining that Pegasus could access a device’s camera and microphone, location, messages, documents and applications.
Kontić had never been arrested or detained, underscoring that physical access to her phone was not required.
NSO Group says its technology is intended for government intelligence and law-enforcement agencies fighting serious crime and terrorism. Investigators have not publicly identified who deployed Pegasus against Kontić.
The Israeli company’s technology has previously been found on phones belonging to journalists, activists and politicians worldwide.
U.S. INVESTORS TAKE CONTROL
NSO was blacklisted by the U.S. government in 2021 over concerns about human rights abuses involving its technology. A group of American investors acquired controlling ownership of the company in 2025, but NSO remains headquartered in Israel and operates under Israeli regulatory oversight.
Twelve people contacted SHARE in August after receiving Apple notifications warning that mercenary spyware had targeted their iPhones. They included students, activists, an opposition parliamentarian and a local opposition councilor, Worthy News learned.
The Serbian warnings were part of a much wider threat. Apple sent its latest wave of spyware notifications on August 13 to targeted users in 110 countries. Since introducing the alerts in 2021, the technology giant has notified users in more than 150 countries, although it has not disclosed how many individuals received them.
Citizen Lab has analyzed one of the 12 Serbian cases and confirmed the Pegasus infection. It considers the remaining 11 devices presumed infected while forensic examinations continue.
Among those receiving a warning was Milica, a student at the University of Niš, who described the potential intrusion as extending far beyond her political activities.
PRIVACY FEARS GROW
“They had access to my entire life, every part of it, not just student meetings,” she recalled. “They could turn on the camera while we were showering, while we were talking about private things.”
“It is not normal that someone records us, and it is not normal that we don’t have a right to privacy,” Milica added.
Two additional cases involved NoviSpy, surveillance software first uncovered in Serbia in 2024. Advocacy group Amnesty International previously documented its use against journalists and activists and described Serbia as a “digital prison.”
Unlike the remote Pegasus attack, NoviSpy requires physical access to a device but can then collect information and remotely activate its microphone or camera.
In one case, NoviSpy was found on the phone of a student movement member whose device police confiscated during questioning.
SERBIAN SECURITY LINK
Earlier investigations found that data collected by NoviSpy was configured to be sent to an internet address linked to Serbia’s Security Information Agency, known as the BIA.
The revelations come as President Aleksandar Vučić prepares for highly charged parliamentary elections expected in October, when the student movement could pose the strongest challenge to his governing camp.
The movement emerged from mass demonstrations following the November 2024 collapse of a railway station canopy in the northern city of Novi Sad, which killed 16 people and fueled public anger over alleged corruption and government accountability.
The protests grew into one of the most serious challenges to Vučić, who has dominated Serbian politics for more than a decade, serving as prime minister before becoming president in 2017.
Citizen Lab researcher John Scott-Railton described the latest Apple warnings as evidence that Serbia’s peaceful pro-democracy movement was being “aggressively targeted with mercenary spyware” ahead of key elections.
PEGASUS USED IN HUNGARY
Serbia is not the first country in the region where Pegasus has raised concerns. In neighboring Hungary, under former Prime Minister Viktor Orbán, forensic investigations confirmed the Israeli spyware had infected phones of several journalists and government critics, while more than 300 Hungarian telephone numbers appeared among potential surveillance targets.
A senior official of the then-ruling Fidesz party later acknowledged that Hungary’s Interior Ministry had purchased Pegasus.
National Assembly President Ana Brnabić, a close Vučić ally, dismissed the Serbian students’ allegations as “utter nonsense” and suggested they were intended to undermine confidence in the upcoming election.
Serbian authorities have previously rejected allegations that they systematically repress or illegally monitor political opponents.
SHARE says the 14 cases documented this year represent the largest known wave of advanced spyware targeting in Serbia, raising questions about who had access to the technology as the country approaches a potentially pivotal election.
GOVERNMENT-ONLY CUSTOMERS
The question is particularly sensitive because NSO says it supplies Pegasus only to government intelligence and law-enforcement customers.
Apple describes mercenary spyware attacks as exceptionally costly and sophisticated and says they have historically been associated with state actors.
The company stresses that such attacks target only a tiny proportion of its customers, often journalists, activists, politicians and diplomats.
Apple does not attribute its threat notifications to specific attackers or countries.
Worthy News reports from a biblical worldview with a commitment to accuracy, transparency, and editorial independence. Learn more about About Worthy News, our Editorial Standards, AI Use Policy, Ownership of Worthy News, News Tips and Corrections, and Worthy News Staff.
💡 Did you know? One of the best ways you can support Worthy News is by simply leaving a comment and sharing this article.
📢 Social media algorithms push content further when there’s more engagement — so every 👍 like, 💬 comment, and 🔄 share helps more people discover the truth. 🙌
Latest Worthy News
If you are interested in articles produced by Worthy News, please check out our FREE sydication service available to churches or online Christian ministries. To find out more, visit Worthy Plugins.
