Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
-
Analysis from Citizen Lab, working alongside the SHARE Foundation, has confirmed that the iPhone of a member of Serbia’s student protest movement was compromised with NSO Group’s Pegasus spyware. The investigation points to the use of an iMessage zero-click exploit to deliver the malware, meaning the attack required no interaction from the victim.
High-confidence indicators of compromise were identified on the device, aligning with previously documented Pegasus infection vectors. The discovery underscores the continued use of commercial surveillance tools against civil society actors, particularly those involved in political activism.
- The infection was carried out via an iMessage zero-click exploit.
- The device belonged to a member of Serbia's student protest movement.
- The analysis was a joint effort between Citizen Lab and the SHARE Foundation.
The findings highlight the risk posed by zero-click vulnerabilities in widely used messaging platforms. For organizations or individuals in high-risk professions, it is worth reviewing device security settings and considering lockdown modes where available, though the specifics of this exploit chain have not been fully disclosed.
Source: The Hacker News
With this level of sophistication in delivery, how is your organization approaching the threat of zero-click mobile exploits, and what mitigation steps are you prioritizing?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login