Serbian authorities used Cellebrite mobile forensic tools to unlock phones and install NoviSpy spyware on devices belonging to journalists and civil society activists during police interviews, enabling extensive surveillance of their communications and activities.
Between 2021-2024, Serbian police and the Security Information Agency (BIA) conducted a systematic surveillance campaign against civil society using advanced digital forensic tools. The authorities used Cellebrite UFED products, mobile forensic tools capable of extracting data from locked smartphones, in combination with a domestically-produced Android spyware called NoviSpy. The spyware was covertly installed on victims' devices during police interviews when phones were temporarily confiscated. At least 13 people were directly targeted including independent journalist Slavisa Milanov in February 2024, environmental activists, and members of organizations like Krokodil. The NoviSpy spyware could capture screenshots, access contacts, turn on microphones and cameras remotely, and upload data to BIA-controlled servers. Technical evidence shows dozens or potentially hundreds of unique devices were targeted. Amnesty International's forensic analysis also uncovered zero-day Android vulnerabilities being exploited by Cellebrite tools. The surveillance campaign occurred amid increasing state repression following anti-government protests, with authorities using the extracted data to map social networks of protest movements and intimidate civil society organizations.
Domain classification, causal taxonomy, severity scores, and national security assessments were LLM-classified and may contain errors.
Using AI systems to conduct large-scale disinformation campaigns, malicious surveillance, or targeted and sophisticated automated censorship and propaganda, with the aim of manipulating political processes, public opinion, and behavior.
AI system
Due to a decision or action made by an AI system
Intentional
Due to an expected outcome from pursuing a goal
Post-deployment
Occurring after the AI model has been trained and deployed