September 23, 2026 MarketsNXT Impact

The Spyware That Targeted Student Protesters Has Made Mobile Device Security a Government Procurement Priority

By Markus Weidemann | Principal Researcher, Insights Economy & Market Intelligence
8 min read

The Zero-Click Attack That Nobody Saw Coming and Nobody Could Stop

On September 2, 2026, the SHARE Foundation, a Belgrade-based digital rights organisation, published forensic findings documenting the largest confirmed wave of mercenary spyware surveillance in Serbia's history: at least fourteen individuals including student movement members, civil society activists, a member of parliament, and a local councilor had been targeted with advanced commercial spyware, with the Citizen Lab at the University of Toronto independently confirming a Pegasus infection on the iPhone of a student activist whose device had received no suspicious link, no malicious file, and no interaction of any kind from the user before the compromise occurred. The iMessage zero-click exploit, which the Citizen Lab traced to a period between December 2025 and January 2026 and whose delivery mechanism required only that the target's phone number be known to the attacker, represents the most commercially significant technical advance in commercial spyware capability: the elimination of the human interaction requirement whose social engineering component had historically been the primary vector for spyware delivery and whose absence from the zero-click attack means that the target's security awareness, however high, provides no protection against a sufficiently sophisticated attacker with access to the exploit. Apple's detection of the infection and its threat notification to affected users, sent in August after the company's Blastpass detection system identified the Pegasus infection signatures, triggered the SHARE Foundation investigation that produced the forensic confirmation: without Apple's monitoring infrastructure, the infections would have remained undetected for months or years longer.

The commercial mobile threat defence market, valued at approximately $3.8 billion in 2026 and growing at over twenty-five percent annually toward $9 billion by 2031, is the commercial security category whose growth is being driven by the convergence of three factors: the proliferation of commercial spyware capabilities from NSO Group and its competitors including Intellexa, Cy4Gate, and the post-acquisition entities whose technology the original NSO team members have carried into new ventures; the expanding target set of government-directed spyware deployment from the original journalists and human rights defenders of the 2019 Pegasus Project exposures to the political opposition members, student activists, and business executives that the 2026 Serbian cases document as the new targeting normal; and the enterprise and government awareness that employee smartphones carrying sensitive communications, authentication credentials, and confidential documents are the primary attack surface that the sophisticated spyware exploits are targeting because the mobile endpoint is where senior officials, board members, and executives conduct the most sensitive communications whose interception creates the highest intelligence value for the attacker.

Apple's Threat Notification System and the Detection Infrastructure

Apple's Blastpass detection system, whose development following the Citizen Lab's 2021 documentation of Pegasus infections on iPhones prompted the company to build automated detection capabilities for the behavioural anomalies, network traffic patterns, and process execution characteristics that commercial spyware installations produce, has become the most commercially significant threat detection infrastructure in the mobile security market by virtue of the scale at which it operates. Its August 2026 notification to users in one hundred and ten countries whose devices it had identified as likely targets of mercenary spyware, the same notification wave that triggered the Serbian students' forensic investigation, represents the systematic monitoring of hundreds of millions of iPhones against the spyware signatures that Citizen Lab, Amnesty International's Security Lab, and Apple's own security researchers contribute to the detection database. Lookout, the US mobile security company whose government and enterprise mobile endpoint security products are deployed across US federal agencies, allied government departments, and large enterprise security programmes, has built its commercial position on the combination of mobile threat intelligence from its detection of over two hundred million mobile devices globally and the enterprise mobile security platform that allows security operations teams to identify, investigate, and respond to mobile device compromise in the organisational fleet that government procurement offices cannot rely on Apple's consumer-oriented notification system to protect systematically.

iVerify, the US mobile security company spun out of the Trail of Bits security research firm, has developed the commercial product that most directly addresses the individual device threat assessment need whose market the Serbia spyware cases have demonstrated: a mobile device security scan that analyses a device's running processes, installed configurations, and system logs for the indicators of compromise that commercial spyware installations leave and that the average enterprise mobile device management system cannot detect because the MDM's visibility is limited to the application layer that spyware specifically avoids. Its basic scan, available as a consumer product, and its iVerify Enterprise platform for organisational deployment have seen demand acceleration from the government and political party security communities whose exposure to state-directed spyware targeting the Serbia cases have made the most acute commercial driver of mobile security investment.

The NSO Group Regulatory Status and Its Market Consequence

NSO Group, the Israeli commercial spyware company whose Pegasus product is confirmed in the Serbian infections and in more than fifty countries of documented deployment since the 2021 Pegasus Project investigation, is operating in 2026 under the ownership of a US investment group that acquired the company in 2025 despite the US Department of Commerce Entity List designation that NSO has been subject to since 2021 and that restricts US companies from exporting to it. The EU MEPs' September 4 demand for immediate European Commission action on Serbia's spyware deployment, and the Citizen Lab's documentation of the first forensically confirmed Pegasus infection of 2026, create the regulatory and political pressure that the NSO Group's new ownership must navigate alongside the commercial spyware market's continuing demand from government customers whose procurement of commercial spyware capabilities, legal under international law for domestic intelligence and law enforcement purposes, continues despite the reputational and legal consequences that documented abuse cases create.

Top 10 Companies in Mobile Device Security and Spyware Detection Globally

  1. Lookout: US mobile security company with government and enterprise mobile endpoint security deployed across US federal agencies; its mobile threat intelligence from 200 million devices and its government procurement relationships create the mobile security company whose detection capability and federal deployment scale make it the commercial leader in the government mobile security procurement market that the spyware incidents are accelerating.
  2. iVerify: US mobile security company with device compromise scan detecting commercial spyware indicators; its Trail of Bits security research heritage and its individual and enterprise scan products create the mobile security company whose direct spyware detection capability most specifically addresses the threat profile that the Serbia Pegasus cases have made the primary commercial driver of mobile security procurement.
  3. Jamf Protect: US Apple device management company with Jamf Protect threat prevention for managed iPhone and Mac fleets; its Apple-native security and its enterprise device management integration create the MDM-plus-security company whose deployment in large enterprise and government Apple device fleets provides the most operationally integrated mobile security capability for the organisations whose iPhone fleets are the primary spyware target.
  4. Apple (Blastpass / BDP): US technology company with Blastpass detection system and threat notification infrastructure that identified Serbian student Pegasus infections; its detection of likely mercenary spyware across 110 countries and its lockdown mode for high-risk users create the device manufacturer whose built-in security monitoring is the most widely deployed commercial spyware detection capability by scale of protected devices.
  5. Zimperium: US mobile threat defence company with z9 on-device machine learning detection for iOS and Android; its on-device threat detection and its enterprise mobile security platform create the mobile security company whose machine learning-based anomaly detection approach identifies mobile threats without requiring cloud telemetry upload, addressing the data sovereignty requirements of government mobile security deployments.
  6. Citizen Lab (University of Toronto): Canadian internet security research organisation with independent forensic verification of commercial spyware infections; its Pegasus confirmation in the Serbia student case and its methodology for detecting mercenary spyware create the academic security organisation whose threat intelligence publications are the primary evidentiary source for both government policy responses to commercial spyware proliferation and commercial mobile security product development.
  7. Amnesty International Security Lab: International human rights organisation with mobile forensics capability for documenting state-sponsored spyware targeting of civil society; its confirmation of NoviSpy infections in the Serbia cases and its MVT Mobile Verification Toolkit open-source detection tool create the NGO whose mobile forensics work provides both the detection documentation and the open-source tool that enables lower-cost spyware detection at scale.
  8. CrowdStrike: US cybersecurity company with Falcon mobile threat defence for enterprise iOS and Android; its integration with the CrowdStrike Falcon platform and its enterprise security operations centre integration create the enterprise security platform whose mobile extension allows organisations with existing CrowdStrike deployment to extend their EDR capability to the mobile endpoints that spyware campaigns specifically target.
  9. SentinelOne: US cybersecurity company with mobile threat detection integrated into its Singularity platform; its AI-based threat detection and its enterprise security platform integration create the EDR company whose mobile security extension addresses the convergence of mobile and endpoint security that enterprise security teams are managing as the boundary between corporate device and personal smartphone dissolves.
  10. Access Now (Digital Security Helpline): International digital rights organisation with Digital Security Helpline providing spyware detection and remediation for at-risk individuals; its free forensic assessment and its rapid response for journalists, activists, and political figures whose phones may be compromised create the civil society security resource whose commercial model, donor-funded rather than commercial, fills the security gap for the individuals most frequently targeted by commercial spyware whose personal resources do not include enterprise security budgets.

Back to All Insights
×