Connect with us

Infosecurity

Serbian Student Activist’s iPhone Hacked via Pegasus Zero-Click Exploit

Published

on

Pegasus zero-click exploit

Serbian Activist Targeted in Silent iPhone Hack

An activist tied to Serbia’s student protest movement had their iPhone silently compromised by NSO Group’s Pegasus spyware. The attack used an iMessage zero-click exploit, according to a forensic report from the Citizen Lab and the SHARE Foundation.

The researchers found high-confidence signs of infection on the device spanning December 2025 and January 2026. They caution that this doesn’t rule out earlier or later breaches. The victim agreed to go public but chose to stay anonymous. The exact infection date was withheld to shield their privacy.

This isn’t an isolated incident. It’s part of a broader pattern of surveillance targeting Serbia’s pro-democracy voices.

How the Pegasus Zero-Click Exploit Worked

The September 2 research detailed an iMessage zero-click exploit. The Citizen Lab believes Apple patched this vulnerability in iOS 18.4.1, released in April 2025. Yet the damage was already done.

Zero-click means the target does nothing. No link to tap. No attachment to open. The spyware simply arrives and takes hold.

The infection would have been invisible to the owner. Once inside, Pegasus grants total access. Notes, photos, even encrypted messages become readable. The attacker can silently switch on the microphone and camera. That level of access is chilling for anyone, but especially for someone involved in political activism.

What the Victim Experienced

The investigation started after the activist received an Apple Threat Notification. That alert flags potential targeting by mercenary spyware.

It was one of at least 14 such notifications documented by the SHARE Foundation. The recipients included student movement members, civil society figures, and an opposition member of parliament. The Citizen Lab noted the timing — ahead of key 2026 election cycles.

Serbia’s Long History of Spyware Abuse

This case doesn’t exist in a vacuum. The Toronto-based lab points to a longer record of surveillance abuses in Serbia.

There have been previous Pegasus infections of civil society. More recently, forensic tools from Cellebrite were allegedly used to plant NoviSpy spyware. On the same day as this report, the SHARE Foundation and Amnesty Tech confirmed finding a new NoviSpy variant on another student activist’s device.

The pattern is clear. The Serbian government has repeatedly denied involvement, but the evidence keeps mounting. For a deeper look at how these tools are used, see our analysis of commercial spyware proliferation.

Got an Apple Threat Notification? Here’s What to Do

The Citizen Lab’s advice is blunt: treat the notification as presuming infection. Don’t wait. Seek expert help immediately.

Their recommendations go beyond the individual. Close contacts — family, collaborators — should also get screened. People at heightened risk should enable Apple’s Lockdown Mode. And everyone should keep devices updated.

If you’re in Serbia, the SHARE Foundation is the first port of call. Elsewhere, trusted experts like Access Now’s Digital Security Helpline can help. The lab acknowledges there’s no substitute for personalized advice, but points to resources like Security Planner for initial guidance.

What Lockdown Mode Actually Does

Lockdown Mode is Apple’s hardened security state. It restricts certain functions to block common spyware vectors. It’s not perfect, but it raises the bar significantly.

For activists, journalists, and anyone else in the crosshairs, it’s a sensible precaution. Combine it with regular updates and you reduce your attack surface considerably.

Continued Targeting of Serbia’s Pro-Democracy Movement

The Citizen Lab’s forensic work on other notification cases is ongoing. This confirmation demonstrates that Serbia’s pro-democracy movement remains in the crosshairs.

The timing is no accident. With elections approaching, silencing dissent becomes a priority for those in power. The use of zero-click exploits makes that silencing easier — and harder to detect.

For those concerned about their own devices, understanding how spyware infects iPhones is the first line of defense. The second is knowing what to do when you get that alert.

This case is a reminder that digital security isn’t just about strong passwords. It’s about recognizing that some attackers don’t need you to make a mistake. They just need your phone number.

Continue Reading

Infosecurity

Outsider Phishing Kit Survives Takedown: 700 New Pages Emerge

Published

on

Outsider phishing kit

A Takedown That Didn’t Stick

The Outsider phishing kit was supposed to be dead. In June, the FBI announced Operation Ghost Hook, a coordinated strike with Google and Lumen’s Black Lotus Labs that seized core admin servers, a Shopify storefront, roughly $100,000 from payment wallets, and thousands of domains. The message was clear: this phishing-as-a-service operation was finished.

It wasn’t.

New research from Group-IB, published on September 3, reveals the Outsider phishing kit has simply adapted. Within a month of the takedown, researchers identified more than 700 new phishing pages tied to the operation. The infrastructure took a hit, but the affiliates kept working.

Tracking the Outsider Phishing Kit’s Reach

Group-IB has been watching this threat actor, known as ChenLun, for a while. Between December 2025 and May 2026, the researchers logged over 100,000 phishing pages targeting at least 54 countries. Before Operation Ghost Hook, they had linked more than 10,000 unique domains to the kit.

The post-takedown surge of 700-plus new domains tells a troubling story. The affiliates who bought access to the Outsider phishing kit didn’t abandon ship when the FBI came knocking. They found new hosting, registered fresh domains, and kept running campaigns.

What the Kit Offers

The platform itself is remarkably polished. Group-IB found 267 ready-made phishing templates covering financial services, brokerage firms, telecom providers, postal services, government agencies, and toll systems. Campaigns spread through SMS, with the kit sold and managed through a Telegram ecosystem.

ChenLun has since deleted that Telegram channel. Before it vanished, the main group boasted over 5,000 subscribers and more than 230 paying customers.

AiTM Capabilities and Real-Time Data Theft

What makes the Outsider phishing kit particularly dangerous is its adversary-in-the-middle (AiTM) functionality. This isn’t a static clone page. Operators can interact with victims live during the phishing flow.

Think about what that means in practice. A victim lands on a fake portal. The operator can dynamically serve SMS, email, PIN, or app-based multifactor authentication challenges. They can redirect victims back to earlier pages to ask for additional payment details. The whole thing runs on WebSockets, providing live communication between the phishing page and an operator panel.

Group-IB identified JavaScript components that capture financial details, bank credentials, PayPal information, and authentication codes. The kit even tracks victims across browser sessions and detects security crawlers. Data entered by victims transmits in real time — including when someone abandons a form before hitting submit.

A Singapore Smishing Campaign Under the Microscope

To show how this plays out in the wild, researchers examined a smishing campaign impersonating Singapore’s Land Transport Authority (LTA). The messages created urgency around a supposed data synchronization issue. They even included instructions telling recipients how to disable their phone’s spam filtering.

The cloned portal collected vehicle registration numbers and phone numbers before redirecting victims to fraudulent payment screens. Those harvested numbers weren’t just for show. Group-IB said they were intended for intercepting SMS authentication codes at a later stage.

Spotting the Pages Before They Strike

There’s a silver lining for defenders. The phishing pages follow a consistent file-naming convention, with an alphabetical prefix marking the victim’s stage in the attack flow. Group-IB recommends organizations track new pages through those file-name signatures to trigger faster takedowns.

The company also advises continuous monitoring for SMS-linked brand abuse. For individuals, the guidance is straightforward: verify alerts through official apps rather than clicking links in messages.

This saga echoes other recent takedown attempts. The Tycoon2FA phishing service resumed activity post-takedown, showing that disrupting these operations requires ongoing effort, not just a single coordinated strike.

The Outsider phishing kit’s survival raises uncomfortable questions about how we combat cybercrime. When the infrastructure falls, the affiliates scatter — and often, they simply rebuild elsewhere.

Continue Reading

Infosecurity

Spyware campaign targets Serbian opposition figures, activists and student protesters

Published

on

Serbian opposition spyware

Spyware hits a broad swath of Serbian civil society

At least 14 Serbians have been caught in a spyware dragnet since December, with victims ranging from a sitting member of Parliament to student protesters who helped organize election efforts. Digital forensic researchers say the campaign appears timed to political events — local elections in March and a likely parliamentary vote this fall.

The SHARE Foundation, a Serbian digital rights group, launched its investigation after a dozen people came forward in August saying Apple had alerted them to possible state-sponsored hacking. In some cases, the alerts were justified: researchers found actual infections.

Two distinct types of spyware were identified on victims’ phones, according to the foundation’s report.

Pegasus and NoviSpy both found on victims’ devices

Experts at the Citizen Lab at the University of Toronto confirmed that one student protester’s phone was infected with zero-click Pegasus spyware between December 2025 and January 2026. Zero-click means no interaction from the victim was needed — no rogue link tapped, no malicious attachment opened.

Amnesty International, which peer-reviewed the SHARE Foundation’s findings, verified that a newer Android spyware called NoviSpy was used in at least two cases. Researchers are still examining 11 more phones whose owners received Apple threat notifications.

Donncha Ó Cearbhaill, who heads Amnesty’s Security Lab, told Recorded Future News the new NoviSpy variant “appears to have been updated to avoid detection.”

A chilling detail: texts read live on TV

One confirmed NoviSpy victim had text messages read aloud on a Serbian television network known to be friendly with the ruling party, the SHARE Foundation said. That detail underscores how surveillance can feed directly into propaganda.

Pattern of repression, or “trivial sensationalism”?

Ó Cearbhaill framed the spyware as one piece of a larger puzzle. “Combined with the excessive use of force against protesters, arbitrary arrests and unfounded criminal and misdemeanor charges, as well as vicious smear campaigns targeting individuals involved or perceived to support the anti-government protests, digital surveillance is yet another element of a broader pattern of systemic repression of critical voices,” he said.

Serbian authorities deny the allegations. The country’s intelligence agency, the BIA, dismissed the findings as “nothing more than trivial sensationalism,” adding that the accusations “clearly indicate the true intentions of the individuals and organisations making them, namely, acting in the interests of certain foreign intelligence services and pressure groups.”

Notably, the spyware activity tracked with the March local elections, which student protesters were deeply involved in. They were pushing to oust the ruling party, which critics describe as increasingly authoritarian.

Serbia has form when it comes to phone hacking

This isn’t a first for Serbia. The country has previously been caught targeting protesters, journalists and dissidents with both Pegasus and NoviSpy.

  • In March 2025, Amnesty said its forensic researchers found two investigative journalists in Serbia had been targeted with Pegasus.
  • A month earlier, Amnesty reported that Cellebrite — whose phone-breaking software lets governments extract data from devices — cut ties with Serbia after an Amnesty report documented NoviSpy being used against dissidents and journalists whose phones were taken while in government custody.

Police never asked detainees for their passwords in those cases, Amnesty said. Instead, they used Cellebrite to break in, then implanted the spyware.

The key difference between the two spyware types: NoviSpy requires physical access to the phone, while Pegasus can slip in remotely with zero interaction. That’s why many NoviSpy infections in Serbia have been discovered only after victims were detained and their phones confiscated during questioning.

NSO Group’s decade of promises, same abuses

John Scott-Railton, a Citizen Lab researcher involved in the Pegasus confirmation, pointed to a grim continuity. “Ten years ago, we found Pegasus spyware’s first target, pro-democracy campaigner Ahmed Mansour and he’s still jailed today,” he said. “Today, it’s Serbian students campaigning for democracy.”

“NSO has spent a decade promising reform, lobbying and shuffling ownership structures, and yet the product and the abuses haven’t changed,” Scott-Railton added. The NSO Group did not respond to a request for comment.

Both Pegasus and NoviSpy give operators extraordinary access — photos, contacts, messages, files, and even the ability to switch on microphones to hear conversations happening near the phone, not just on it.

“They are ready to use whatever it takes”

Ognjen Rašić, a third-year student and protester whose phone is still under forensic study, believes he was likely hit with Pegasus. He’s never been in police custody, which a NoviSpy attack would likely require.

Rašić has protested peacefully against the government for years and joined a student election-preparation team about a year ago. The potential infection unsettles him — especially the microphone capability. “The spyware is a strong indicator that our government is very afraid of us,” he said. “They are ready to use whatever it takes to sabotage us because we’re currently the strongest and the most influential political force in Serbia.”

The March elections were plagued by violence and irregularities, he said. Still, he and fellow protesters are pressing on, aiming to win in the parliamentary elections expected this fall.

“I want to send a clear message that I am not afraid and that my colleagues are not afraid,” Rašić said. “We want justice, and I think the most important message is that students will win.”

An MP steps forward

On Wednesday, opposition parliamentarian Radomir Lazović of the Green-Left Front revealed his phone was among the 14 targeted. Forensic work to determine whether the attack succeeded is ongoing, per the SHARE Foundation.

Lazović called on the European Commission in March to act against Serbian President Aleksandar Vučić over rights abuses. The attacks on him and the students show “how [the government] are slipping into some sort of, I don’t know, dictatorship,” he said.

“They want to control the political opponents of the ruling party, which tells you what atmosphere we, as an opposition, are actually working in,” Lazović added. “If they are controlling us, if they’re monitoring us, and they’re tapping our phones and so on, it’s really hard to have any kind of meaningful opposition working in Serbia.”

Ó Cearbhaill warned that such attacks tend to spike around heightened political moments. With early parliamentary elections likely in October, he said, “we are increasingly concerned about the safety of student protesters and civil society in general.”

Continue Reading

Infosecurity

Two Decades of Malice: How an International Takedown Finally Struck at the Sality P2P Botnet

Published

on

Sality P2P botnet

Operation Strikes at a 20-Year-Old Menace

For more than two decades, the Sality P2P botnet has been a quiet, persistent threat. On August 31, that all changed. A US-led law enforcement operation, with help from Bulgaria, Hungary, Romania, and Europol, dealt a significant blow to this sprawling network.

The private sector played a key role too. CrowdStrike and the Shadowserver Foundation lent their technical muscle to the effort. Their goal? To sever the botnet’s decentralized communication lines and finally start cleaning up the mess.

Why Sinkholing Is the Go-To Tactic

Disrupting a P2P botnet isn’t like taking down a traditional one. There’s no single command-and-control server to seize. Instead, infected machines talk directly to each other. That’s what makes them so resilient.

The operation’s core strategy was sinkholing. This technique redirects traffic from infected machines away from the botnet’s real infrastructure. It’s a clever way to isolate the network and observe its behavior without letting it function normally.

Europol noted this wasn’t a spur-of-the-moment decision. They’ve been tracking Sality-related infrastructure since 2017. In the weeks before the takedown, coordination intensified with weekly operational calls among all partners.

The Role of ISPs and CSIRTs

While authorities seized domains linked to Sality, the Shadowserver Foundation worked behind the scenes. They coordinated with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infections and notify victims. The US Justice Department emphasized this victim-notification effort as a critical part of the overall strategy.

The Scale of the Sality Botnet

Sality isn’t just old; it’s massive. Europol reports that at its peak, the botnet boasted over one million infected machines. These were unwitting participants in crypto-theft and other malicious schemes.

Over the years, more than 11 million unique IP addresses have been linked to Sality’s infrastructure. That’s a staggering footprint for any cybercriminal enterprise.

CrowdStrike’s analysis paints an even more detailed picture. They claim the botnet operator distributed malicious payloads to over 15,000 machines. These payloads included credential theft tools, spam distribution software, proxy services, and DDoS attack mechanisms.

Exploiting Sality’s Trust Flaw

Here’s the interesting part: the takedown worked by turning Sality’s own design against it. CrowdStrike explained that every Sality bot maintains a list of known super peers. These are publicly reachable infected machines that form the backbone of the network.

Every 40 minutes, each bot checks whether its stored peers are still online. Peers that respond gain reputation. Those that don’t lose it and are eventually purged from the list. This verification process was the weak link.

The disruption team exploited this by:

  • Removing legitimate peers through protocol-level manipulation during the verification phase.
  • Inserting sinkhole entries into the emptied peer lists. This allowed them to track progress and notify victims effectively.

The result? A botnet that once seemed untouchable is now struggling to maintain its grip on infected machines worldwide.

What This Means for the Future of Botnet Disruption

This operation proves that even the most resilient P2P networks have vulnerabilities. It also highlights the importance of international cooperation. No single country could have pulled this off alone.

For anyone concerned about P2P botnet threats, this is a positive sign. It shows that law enforcement and private security firms can work together effectively against even the most entrenched cybercriminal infrastructure.

Still, experts caution that Sality isn’t completely dead. The sinkholing has disrupted operations, but the underlying malware remains on infected machines. Continued vigilance from ISPs and individual users will be essential to fully eradicate this decades-old threat.

Continue Reading

Trending