Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recurring advanced-spyware targeting of political and civic figures in Serbia since early 2026

Trend
First reported
Last updated
Happening score
H score 7
1 unique sources, 1 articles

Summary

Hide ▲

At least 14 people in Serbia have been targeted with advanced spyware since early 2026, concentrating risk on student movement members, activists, and opposition figures. The recurring pattern suggests sustained surveillance pressure against politically active people rather than a one-off device compromise.

Related Happenings

Member of Serbia's student protest movement hit by network compromise linked to NSO Group

Incident
H score9 First: 03.09.2026 11:43 Last: 03.09.2026 11:43 Sources 1

How related: "Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said.

About this happening: The iPhone of a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware through an iMessage zero-click exploit, creating a high-c...

Jewelbug pairs espionage with industrial-scale cryptocurrency fraud

Threat Actor Meta
H score62 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

About this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...

GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy

Malware Activity
H score41 First: 29.05.2026 01:24 Last: 29.05.2026 01:24 Sources 1

About this happening: GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...

NCSC-UK joint advisory on covert botnets and proxy networks

Public Sector Action
H score66 First: 23.04.2026 15:28 Last: 23.04.2026 15:28 Sources 1

About this happening: NCSC-UK and partner agencies issued a joint advisory warning that China-nexus hackers are using hijacked consumer devices as covert proxy networks to hide maliciou...

Iranian MOIS Telegram malware campaign targeting opposition groups

Campaign
H score32 First: 23.03.2026 11:45 Last: 23.03.2026 11:45 Sources 1

About this happening: The FBI warned that Iranian MOIS-linked hackers are using Telegram C2 and social engineering to deliver Windows malware against journalists, dissidents, and ot...

Timeline

  1. 03.09.2026 11:43 2 articles · 2h ago

    Recurring advanced-spyware targeting of political and civic figures in Serbia since early 2026

    Initial Disclosure

    By early 2026, Serbia was seeing a recurring spyware targeting pattern focused on politically active and protest-linked people. The concentration of cases around opposition and student movement figures points to sustained surveillance pressure on civic actors.

    Show sources