Serbian Civil Society Targeted in Largest Documented Spyware Wave
How Did the Spyware Infiltrate Devices?
At least 14 individuals from Serbian civil society, including student protesters, were infected with advanced spyware earlier this year in what digital rights group Share Foundation described as the largest documented wave of such surveillance in the country’s history. The infections were identified in August after Apple issued security alerts to users in 110 countries who had been targeted by state-linked mercenary spyware. Share Foundation confirmed the targeting of activists, journalists, and legal professionals critical of government policies.
Breaking news:
The spyware used in the attacks is believed to be capable of extracting messages, photos, location data, and microphone and camera access without user interaction. Share Foundation’s investigation revealed that the victims were targeted between January and August 2024, coinciding with increased public dissent over environmental policies and judicial reforms. The group emphasized that the scale and sophistication of the operation suggest state involvement, though no official attribution has been made. Apple’s threat notifications, which began in 2021, are designed to warn users of likely state-sponsored spyware infections.
What Are the Implications for Digital Rights in Serbia?
The infections likely occurred through zero-click exploits, meaning victims did not need to click links or download files for the spyware to install. These vulnerabilities are often purchased from private surveillance firms and deployed via messaging apps or web browsers. Share Foundation noted that several victims received no prior warning before Apple’s alert, indicating the attacks were highly stealthy. The group called for an independent forensic audit of affected devices to confirm the extent of data exfiltration.
The wave of infections raises serious concerns about the erosion of privacy and freedom of expression in Serbia, particularly as the country faces scrutiny over democratic backsliding. International observers have warned that the use of spyware against civil society undermines trust in institutions and chills legitimate activism. Share Foundation urged Serbian authorities to investigate the attacks transparently and to ban the use of mercenary spyware within national borders. Without accountability, the group warned, such surveillance could become a recurring tool of repression.
Who were the primary targets of the spyware wave in Serbia? The targets included student protesters, journalists, human rights lawyers, and members of civil society organizations critical of government actions, according to Share Foundation’s findings.
Frequently Asked Questions
How did Apple notify users of the spyware infections? Apple sent threat notifications to users in 110 countries in August 2024, warning them that they may have been targeted by state-sponsored mercenary spyware attempting to compromise their i Phones.
What response has the Serbian government given to the allegations? As of the time of reporting, Serbian officials have not publicly responded to the Share Foundation’s allegations or confirmed any investigation into the spyware incidents.
More stories: