Spyware Hits Serbian Civil Society Ahead of Elections: What We Know

At least 14 people from Serbian civil society were targeted with advanced mercenary spyware since the beginning of 2026, according to findings published by the digital rights group Share Foundation on September 2, 2026 Share Foundation. The infections came to light in August 2026 after Apple sent threat notifications to individuals across 110 countries, warning them they had likely been victims of mercenary spyware attacks. Apple's notification system is built specifically to alert users who may have been individually singled out by these operations Apple Support.
Mercenary spyware refers to highly sophisticated surveillance software sold commercially — often to governments — that can secretly take over a phone or computer. Unlike ordinary malware, these tools are deployed against specific individuals, typically with the goal of extracting messages, calls, photos, and location data without the target ever knowing.
This wave of infections is the largest documented spyware targeting of its kind in Serbia to date, according to Share Foundation. Those affected included members of a Serbian student movement that has opposed the government of President Aleksandar Vučić since 2024, along with activists, a member of parliament, and a local councilor affiliated with opposition parties Share Foundation. The student movement formed out of countrywide protests that followed the collapse of a train station in winter 2024. Reuters reported that the spyware targeting occurred ahead of local elections held in March Reuters.
A technical analysis released by the Citizen Lab on September 2, 2026, confirmed that at least one Serbian individual had been targeted with NSO Group's Pegasus spyware, which gives the attacker full access to the compromised device. NSO Group, which began as an Israeli company with close ties to the military and is now under US ownership, developed Pegasus as a commercial surveillance tool The Guardian.
Ana Brnabić, Serbia's parliamentary speaker and a senior member of the ruling Serbian Progressive Party, denied that students had been spied on. There is no evidence directly attributing the targeting to the government of Aleksandar Vučić The Guardian. The attribution gap is notable: Pegasus is licensed to state clients, but the mercenary spyware market is opaque, and the chain of accountability between a vendor, a government client, and an operator is deliberately difficult to trace. This ambiguity benefits whichever actor deployed the tool.
Share Foundation noted that the timing of the spyware deployment, coinciding with March's local elections, may have served as a practice run ahead of snap elections scheduled for October 2026. The prospect of back-to-back elections adds a structural dimension to the targeting. Surveillance operations coordinated around election cycles can serve to map opposition networks, identify internal communications, and disrupt organizing capacity at critical moments. The shift from local to snap national elections raises the stakes for civil society actors who were already in the crosshairs.
The targeting of a sitting member of parliament and a local councilor alongside student organizers broadens the profile of those affected beyond grassroots activism and into formal political opposition. This cross-section suggests that the operational intent may have been to gather intelligence across multiple tiers of the opposition's infrastructure simultaneously.
Share Foundation has previously provided resources to help individuals understand and mitigate these risks. In September 2025, the organization published "Citizens' Nightmare: A Manual for Understanding Spyware," a guide explaining the mechanics and use of spyware tools Share Foundation. The current findings validate the threat model the group outlined in that manual, moving from general risk assessment into documented, device-level compromise.
The confluence of Apple's global notification mechanism, Citizen Lab's forensic confirmation of Pegasus, and Share Foundation's on-the-ground documentation creates a layered verification of the incident. Each source contributes a distinct piece of the picture: Apple's infrastructure-level detection, Citizen Lab's technical confirmation of the specific payload, and Share Foundation's mapping of the targets' political and civil society roles. The denial from parliamentary speaker Ana Brnabić stands against this technical backdrop, setting up a familiar tension between forensic findings and political responses.
The broader context here is that commercial spyware vendors enable state-level surveillance capabilities without direct attribution. The deployment of Pegasus against Serbian civil society actors ahead of a national electoral cycle places this event within a recurring framework where surveillance and democratic processes intersect. The October 2026 snap elections will be a focal point for whether the operational logic identified by Share Foundation's March election analysis extends into the national campaign.
The verified facts establish the mechanics of the targeting, the identities of those affected, and the technical capabilities of the tools deployed. What remains outside the verified record is the identity of the operator. The political environment in Serbia, characterized by an entrenched ruling party and an opposition that crystallized through public protest, provides the setting. The spyware provides the instrument. The gap between the two is where accountability would normally reside, and it is precisely that gap that the current evidence does not close.


