Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
Summary
The iPhone of a Serbian student protest movement member was infected with NSO Group's Pegasus spyware. Citizen Lab's analysis confirmed that an iMessage zero-click exploit was used to deploy the spyware onto the device.
IFF Assessment
The use of Pegasus spyware, particularly via a zero-click exploit, represents a sophisticated threat to individuals and movements, undermining privacy and security.
Severity
A zero-click exploit targeting iMessage on iPhones is highly severe, allowing for infection without user interaction and potentially leading to full device compromise. The impact includes complete confidentiality, integrity, and availability loss.
Defender Context
This incident highlights the persistent threat of sophisticated spyware like Pegasus, often targeting activists and dissidents. Defenders should be aware of advanced exploit techniques, including zero-click vulnerabilities in widely used messaging applications, and monitor for indicators of compromise associated with state-sponsored surveillance tools.