The Security Information Agency (BIA; Bezbednosno-informativna agencija) is Serbia’s security and intelligence agency. It has been technically linked to prior NoviSpy Android spyware infrastructure: NoviSpy samples identified in 2024 were configured to exfiltrate collected data to server infrastructure associated with the agency. BIA has also been associated with the use of Cellebrite forensic tooling against journalists and activists. Subsequent spyware targeting in Serbia affected student-movement members, civil-society activists, and opposition politicians, including confirmed Pegasus and NoviSpy infections. Available evidence does not publicly establish definitive attribution of the 2026 Pegasus activity, or all NoviSpy infections, to BIA.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Suspected Serbian state-security actor conducting targeted surveillance of student protesters, civil-society activists, politicians, and journalists using NoviSpy and Pegasus, including apparent device compromise after police seizure or detention.
Service de sécurité serbe lié dans le rapport à une précédente campagne NoviSpy contre des personnes politiques et civiles. La campagne documentée en 2026 vise des membres du mouvement étudiant, des activistes et des responsables politiques de l’opposition en Serbie; le rapport ne démontre pas explicitement l’attribution opérationnelle de chaque infection Pegasus à la BIA.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.