A documented investigation by SHARE Foundation, an EDRi member organisation, has revealed that opposition-aligned individuals in Serbia fell victim to sophisticated spyware infections beginning in 2026. The victims—numbering at least 14—encompassed student activists, civil society figures, an opposition member of parliament, and an opposition local councilor. The campaign represents Serbia's most extensive known spyware targeting to date. The attacks occurred in the lead-up to municipal elections held on March 29, 2026.

Following detection of the same malware on an additional device, private Viber communications from that phone surfaced publicly on Serbian State-aligned broadcaster Informer. Ongoing forensic investigation has enlisted specialists from Citizen Lab and Amnesty International to examine the infections.

A gross abuse of technology

Spyware tools differ substantially in their deployment mechanisms and technical capabilities. Pegasus, classified as military-grade surveillance software, remains restricted to government purchase and deployment. Its installation occurs without user interaction, and infrastructure components reside within the purchasing nation's territory. The newly identified spyware, by contrast, necessitates direct physical contact with the target device.

Deployment of such invasive surveillance constitutes a fundamental breach of privacy protections and amplifies the intimidation effect experienced by the broader population. This suppression directly undermines associated freedoms—particularly expression and movement—alongside democratic participation more broadly.

The selection of student activists, a parliamentary representative, and a municipal official carries particular significance: such political surveillance directly jeopardizes the principle of equal political competition and compromises electoral legitimacy. Democratic systems require that elected officials maintain unrestricted capacity to exchange information, coordinate activities, and scrutinize governmental conduct without exposure to covert, unlawful monitoring. When political figures lack such protection, ordinary citizens cannot reasonably anticipate their own privacy and democratic freedoms will be safeguarded. Such operations corrode institutional legitimacy and undermine the foundation for authentic political participation.

Under its operational characteristics and intended function, spyware meets the legal definition of a computer virus—executable code that manipulates other software or stored information within computing systems or networked environments—rendering its introduction a criminal violation under Serbia's penal legislation. Spyware deployment grants complete unauthorized access to device contents, inflicting damage not only upon the primary target but also upon any individuals whose information resides on the compromised device.

During the final months of 2024, Amnesty International released findings from forensic examination of infected devices belonging to Serbian users, with participation from the SHARE Foundation. The investigation identified a previously undocumented spyware variant, designated NoviSpy by researchers. Configuration analysis demonstrated that NoviSpy transmitted exfiltrated phone data to a server registered to Serbia's Security Information Agency (BIA). Investigators also established that the malware had been installed on devices—seized during law enforcement questioning of targeted journalists, activists, and nonprofit representatives—through misuse of Cellebrite, a forensic analysis platform that Serbia's Interior Ministry obtained via Norwegian donation. Court proceedings remain pending on criminal charges filed in connection with these incidents.

The approaching electoral period intensifies an already volatile political environment characterized by escalating physical and digital suppression of political opposition, encompassing student movements, media professionals, and advocacy organizations. This digital assault supplements established repression methods including coercive detention and prosecution on unfounded allegations.

What can citizens do to protect themselves?

Apple's iOS and Google's Android operating systems include mechanisms to alert users when their devices have been subject to spyware compromise. Those receiving such warnings should immediately engage qualified security professionals who can assist in data preservation and forensic examination. Beyond routine protective measures—maintaining current software versions and declining suspicious downloads—individuals facing elevated risk profiles—including student organizers, advocacy workers, journalists, and opposition political figures—should activate enhanced device protections: Lockdown Mode for iOS devices and Advanced Protection for current-generation Android systems.

Source: EDRi (European Digital Rights)