Pegasus Spyware Hits Serbian Student Activist via Zero-Click iMessage

Published September 8, 2026

Pegasus spyware can secretly infect iPhones by sending a malicious iMessage. The attacker does not need the victim to open or click anything.

Report priority
Medium

How it works

  • The attacker sends a specially crafted iMessage to the victim's iPhone.
  • The iPhone's iMessage app processes this message automatically, without the user opening or clicking it.
  • This triggers a flaw in iOS that lets the spyware install itself in the background.
  • Once installed, the spyware can secretly monitor calls, messages, and location data.

What to do

Check your iPhone's iOS version by going to Settings > General > About. If it is before iOS 15.6.1, your device is vulnerable. Pegasus spyware can infect you if an attacker sends a malicious iMessage, no action from you is needed.

Update your iPhone to iOS 15.6.1 or later by going to Settings > General > Software Update. This patch fixes the flaw that lets Pegasus spyware install itself automatically. If you cannot update, do not open suspicious iMessages.

Technical details

An attacker sends an iMessage to a Serbian student activist's iPhone. The iPhone receives the message and processes it automatically, installing Pegasus spyware without the user's knowledge.

Pegasus spyware infected a Serbian activist through a zero-click iMessage exploit, part of Serbia's largest spyware wave. Update iOS now.