What Happened to the Serbian Student Movement Member

Between December 2025 and January 2026, an iPhone belonging to a member of Serbia's student movement was infected with Pegasus spyware through a zero-click iMessage exploit. No link was clicked, no attachment opened, and no suspicious message needed to be read. The exploit was delivered and executed silently, giving whoever deployed it access to the device without the owner ever knowing an attack was underway.

The case adds to a long list of documented Pegasus infections involving activists, journalists, and civil society figures worldwide. Pegasus is commercial spyware designed to be installed covertly on mobile phones, and it has repeatedly turned up on the devices of people involved in political organizing, protest movements, and independent reporting. A student movement member being targeted fits a pattern that researchers have tracked for years: the tool is marketed as a law enforcement and intelligence product, but its use has extended well beyond that stated purpose.

How Zero-Click iMessage Exploits Bypass Awareness and VPN Protection

The most important detail in this case is the word "zero-click." Most advice about digital safety assumes an attacker needs the target to do something: click a phishing link, download a malicious file, or approve a suspicious permission. Zero-click exploits remove that requirement entirely. The vulnerability lives in how the device processes incoming data, in this case through iMessage, so simply receiving a message can be enough to trigger the infection.

This is also why a VPN, no matter how well configured, cannot stop this kind of attack. A VPN encrypts traffic between your device and the internet and can hide your IP address or location, but it does nothing to patch a flaw in how your phone's messaging app parses incoming data. The exploit doesn't need to intercept your traffic; it needs your device to receive a single message. Firewalls, antivirus apps, and typical privacy tools built for everyday threats like tracking or data collection were never designed to catch this category of attack, and they generally can't.

If you want a clearer picture of how spyware operates once it's on a device, including how it collects data and communicates back to whoever deployed it, the spyware glossary entry breaks down the mechanics in plain terms.

Why Activists and Journalists Remain Prime Pegasus Targets

Pegasus and similar commercial spyware tools have shown up repeatedly in cases involving people who challenge governments or powerful institutions, rather than in the kind of opportunistic cybercrime most people worry about day to day. Student movements, protest organizers, and independent journalists occupy a category of risk that ordinary consumers rarely face: they are targeted specifically because of who they are and what they do, not because they made a security mistake.

This is part of a broader trend of government and law enforcement bodies acquiring commercial surveillance tools. In the United States, ICE has confirmed using Paragon's Graphite spyware to intercept encrypted communications, and lawmakers in Ireland are advancing a surveillance bill that would legally authorize police use of spyware from vendors with similar reputations. Whether or not any of these specific tools are connected to the Serbian case, the pattern is consistent: commercial spyware vendors sell to governments, and the people most likely to end up on the receiving end are those engaged in activism, journalism, or political dissent.

Practical Steps for High-Risk Users

For most people, standard digital hygiene, strong passwords, two-factor authentication, and a VPN for everyday privacy, remains sound advice. But if you belong to a group that faces elevated risk, such as activists, journalists, or organizers, a few additional steps matter more than the usual checklist:

  • Keep iOS updated immediately. Apple regularly patches the kind of vulnerabilities zero-click exploits rely on, and delaying updates extends your exposure window.
  • Enable Lockdown Mode. Apple's Lockdown Mode restricts several message and attachment processing features specifically to reduce the attack surface that exploits like this one depend on. It's built into iOS settings and designed for exactly this threat category.
  • Assume targeted risk means different rules. If your work makes you a plausible target for state-level surveillance, standard consumer security advice isn't sufficient. Organizations like Citizen Lab and Access Now offer forensic support for people who suspect they've been targeted.
  • Don't confuse real infections with scam scares. Not every claim of Pegasus infection is legitimate. Some scam emails falsely claim your device has been compromised to extort payment. If you've received one of these messages, our breakdown of Pegasus extortion emails can help you tell the difference between a real threat and a scare tactic.

What This Means For You

For the overwhelming majority of people reading this, Pegasus zero-click iPhone spyware is not a realistic personal threat. These tools are expensive, targeted, and reserved for specific individuals rather than deployed broadly. But the case underscores an important distinction: privacy tools like VPNs protect against surveillance of your traffic and location, not against sophisticated exploits that compromise the device itself. If you fall into a higher-risk category, whether through activism, journalism, or political organizing, your security posture needs to reflect that reality rather than relying solely on consumer-grade tools.

Key Takeaways

  • Update iOS as soon as patches are released, since zero-click exploits typically target unpatched vulnerabilities.
  • Enable Lockdown Mode if you're in a high-risk category; it specifically limits the message processing pathways these exploits use.
  • Understand that VPNs and standard privacy apps do not protect against zero-click spyware infections.
  • Seek forensic help from digital rights organizations if you suspect a targeted infection rather than assuming it, and be skeptical of unsolicited emails claiming your device is already compromised.