Press TechRound interviews Secure.com CEO on the future of AI security
Read

Pegasus Landed On An Activist iPhone. Nobody Tapped A Thing.

A zero click iMessage exploit planted Pegasus spyware on a Serbian activist iPhone with no tap at all. Here's how to lower your own risk fast.

Dateline: September 4, 2026

TL;DR: A phone rang with no ring. No text to open. No link to tap. And still, spyware walked right in.

That is what happened to a member of Serbia’s student protest movement. Researchers at Citizen Lab, working with the SHARE Foundation, confirmed the person’s iPhone was infected with Pegasus, the surveillance tool built by NSO Group. The attack used a zero click flaw in Apple iMessage. The victim did nothing wrong and saw nothing at all.

It is the first Pegasus infection of 2026 that Citizen Lab has confirmed by forensics. And it is part of the biggest spyware wave Serbia has ever documented.

What Happened?

The target got an Apple Threat Notification, the warning Apple sends when it believes a device was hit by mercenary spyware. Citizen Lab then pulled forensic evidence off the phone. The verdict was high confidence. The device showed signs of Pegasus activity between December 2025 and January 2026. Researchers could not rule out more infections beyond that window.

The break in came through iMessage. A zero click exploit needs no action from the person holding the phone. No tap, no click, no preview. Apple has since closed the hole, with fixes landing in iOS 18.4.1. Once Pegasus is inside, it owns the phone. Messages, photos, notes, location, even encrypted chats. It can switch on the microphone and camera without a trace.

The person is not alone. The SHARE Foundation counted at least 14 people tied to Serbia’s student movement, civil society, and political opposition who were targeted since early 2026. The list includes a member of parliament and a local councilor.

12 people came forward in August after getting Apple warnings. Investigators also found a fresh build of the NoviSpy spyware on a separate activist’s Android phone, rebuilt to dodge detection.

What’s the impact?

Zero click means the old advice fails. “Do not click strange links” does nothing here. There was no link.

That should worry more than activists. The same class of attack that hits a phone can hit a laptop, a server, or a cloud account through a channel a person already trusts. Attackers keep moving toward paths that need zero human error, because human error is the one defense you cannot patch on a schedule.

The timing also matters. The infections lined up with Serbia’s local elections. Surveillance tools bought for one purpose keep showing up pointed at journalists, students, and opposition figures.

For any security team, the lesson is blunt. If your whole plan depends on people spotting the trap, you have no plan.

How to avoid this

  • You cannot patch a zero click flaw you do not know about. But you can shrink the blast radius and catch what slips through.
  • Screen the close contacts of a confirmed target. One compromised phone exposes everyone who messaged it.
  • Turn on Apple Lockdown Mode for high risk users, and use Android Advanced Protection. Both cut off the features these exploits abuse.
  • Update the operating system the day a patch drops. This attack was killed by a later iOS build.
  • Treat an Apple Threat Notification as a confirmed hit. Get expert forensic help, do not just reboot and hope.
  • Watch behavior, not just known bad files. Odd process activity, strange network calls, and battery or data spikes can flag an infection when there are no clean indicators to match.