Amnesty International: Serbian authorities used phone hacking startup Cellebrite's tools to unlock a journalist's phone before infecting the device with malware
Authorities in Serbia have repeatedly used Cellebrite tools to unlock mobile phones so they could then infect them with potent malware …
404 MediaJoseph Cox
Context & Ripple Effects
Amnesty International's allegation places a law-enforcement forensics vendor in the chain between device seizure and malware deployment. The case later prompted Cellebrite to suspend Serbia as a customer, making vendor controls and customer conduct central to the story.
The reported access path also became a platform-security issue: Amnesty subsequently said Google had patched three Android zero-days tied to the forensic tools. That links handset extraction capabilities to the security of the devices being examined.
First-order effects
The journalist's phone was reportedly unlocked by Serbian authorities and then infected with malware, exposing the person and their communications to potential surveillance.
Cellebrite faces immediate scrutiny over how its tools are used by government customers; the later Serbia suspension shows the allegation had commercial consequences.
Second-order effects
Android and other mobile-security teams face pressure to close vulnerabilities that can turn physical device access into broader compromise, as reflected in the reported Google fixes.
Government buyers and digital-rights groups gain a clearer basis to examine whether forensic-tool procurement, oversight, and use policies distinguish legitimate evidence extraction from enabling subsequent surveillance.
Third-order effects
If similar cases recur, the forensics market may be judged not only on lawful-access claims but also on the downstream misuse risks created by device-unlocking capabilities.
The episode points to a tightening contest between mobile platforms patching exploit paths and surveillance vendors adapting their access techniques, with customer controls becoming a differentiator.
The trend: Commercial mobile-forensics tools are increasingly being assessed as dual-use surveillance infrastructure, not merely as law-enforcement evidence products.
I spoke to Slaviša Milanov, a journalist who was targeted this way. Traffic stop leads to more ‘testing’ at police station; gives police his phone. He notices suspicious stuff afterwards; turns out unlocked with Cellebrite and infected with NoviSpy — www.404media.co/cellebrit…
New, by @lorenzofb.bsky.social: Amnesty says it's identified the first “forensically documented spyware infections” enabled by the use of Cellebrite phone-unlocking tools. The spyware was discovered on a Serbian journalist's phone after a routine traffic stop. — techcrunch.com…
Serbian police and intelligence authorities are using spyware alongside a suite of mobile phone forensic tools to conduct unlawful surveillance against journalists and activists. Digital repression is just one tactic used to silence civil society & peaceful protest in Serbia.
Important work by @amnesty and @BIRNSrbija on the anti-democratic Serbian government's use of highly invasive spyware to surveil its journalists and citizens. https://securitylab.amnesty.org/ ...
🚨 BREAKING: Amnesty's latest report on digital surveillance in Serbia: new *NoviSpy* spyware discovered; zero days identified and patched; and first evidence showing use of Cellebrite UFED forensic products to unlock phones to then infect with spyware. 🧵 [image]
🚨 NEW: Serbian authorities have used highly invasive spyware, including NSO Group's Pegasus, as well as digital forensic tools to target activists & journalists during periods of detention or routine police interviews, @Amnesty investigation reveals. https://securitylab.amnesty.o…