BELGRADE – John Scott-Railton, senior researcher at the Canadian company Citizen Lab, told Insajder web portal that the institution is “very convinced” that there was an attack on the phones of students in Serbia by the Pegasus software, and that “experience tells him that where one security threat appears, there are often many more to follow”.
Scott-Railton explained that their investigation began by collecting forensic clues from the device and searching for signs corresponding to the infection with spyware. He explained that this type of analysis includes a review of logs, as well as other files and artifacts that may remain after exploiting vulnerabilities and infections of devices, adding that they were analyzed for general indicators of intrusion and hacking, as well as indicators associated with specific families of spyware.
“We have found high-reliability indicators indicating NSO Group’s Pegasus spyware, which we have been tracking for more than 10 years, ever since our first Pegasus discovery in August 2016. The indicators were consistent with infection without the need for zero-click interaction via iMessage, meaning the user would not see any warning signs if the device was infected,” Scott-Railton said.
At the press conference of Students in Blockade one of the speakers was student Jelena Kontić, who stated that she was “the first victim of Pegasus in 2026”, and that the possible motive for the attack is that she is very active in the work unit “Student in every village”, the movement’s field campaign.
The Citizen Lab researcher states that apart from notification, there is no other way for a phone user to determine for themselves that they are the target of an attack.
“There is no way in which an ordinary phone user can reliably determine whether they were infected with mercenary spyware like Pegasus. There is no substitute for expert forensic analysis. In my experience, security warnings are like ants in the kitchen: if you see one, there are many more hiding”, he said, adding that this means many more people need to be checked for possible infection with spyware.
Asked if a forensic investigation could determine the perpetrator of the attack, Scott-Railton said reliable evidence could only be found on Pegasus’ servers, he responded that this depended on the specific case, the type of evidence available, and the time that elapsed between the incident and the analysis.
“In this case, our first public conclusion is that the device was infected with Pegasus spyware. Our forensic investigation of this and other cases continues,” he said.
According to Scott-Railton, in order to determine who ordered the attack and where the stolen data was sent, the most reliable data is actually located in the premises of the state authority, Pegasus users.
“NSO Group itself states that Pegasus stores logs of each use on the user’s site. These logs can provide a large number of responses. Such data must be stored immediately so that an independent investigation can determine the extent and extent of the potential abuse,” Scott-Railton noted.