LEAKED INTERNAL DOC – BULKAHACKERS EXCLUSIVE DROP
Classification: HIGHLY CONFIDENTIAL – SERBIAN STATE SURVEILLANCE
Source: Alleged internal BIA / MUP forensic & operational materials
Leaked by: @BulkaHackers – Preshevo Valley Cyber Crew
Date of leak: February 2026
Handle with care – distribution may trigger Article 146 + national security charges
OPERATION “DIGITAL CAGE” – NOVISPY DEPLOYMENT OVERVIEW
Project codename: NoviSpy / NS-Admin
Developer: Internal BIA cyber unit + external contractors (identity redacted)
First known build: Q3 2018
Current active version (2025): v4.2.7 (multiple variants generated per target)
Deployment window: 2019 – ongoing (peak activity 2023–2025 during environmental & anti-corruption protests)
Core objective:
Long-term covert monitoring of persons of interest (POI) classified as threats to public order, state stability, or critical infrastructure narratives.
Primary targets: journalists, environmental activists, student organizers, NGO staff, protest coordinators, independent media figures.
Infection Vector – Physical Access Protocol (Standard Procedure)
1. Subject is brought in for “informal interview”, administrative check, or misdemeanor detention.
2. Device (Android only – iOS not yet supported) handed over or seized temporarily.
3. Cellebrite UFED 4PC / Premier used to:
- Bypass lock (known Qualcomm zero-days + brute-force on older models)
- Extract full filesystem backup
- Install payload without visible traces
4. Two-stage drop:
- NoviSpyAdmin (com.serv.services) – main persistence & exfil module
- NoviSpyAccess (com.accesibilityservice) – screen/content capture via Accessibility abuse
5. Device returned to subject within 30–90 minutes. Subject usually unaware of compromise.
6. Post-install check: device rebooted, ADB debugging disabled, app hidden from launcher.
Active Capabilities – What We Are Pulling (2025 config)
- Full screen recording + screenshots (every 5–30 seconds when active)
- GPS location logged every 10 minutes (even when GPS “off” via fused location)
- Microphone live-stream on demand (up to 48 hours buffered)
- Camera snapshots / short clips on trigger
- All incoming/outgoing SMS forwarded silently
- Call log + contact list exfil
- File exfil: WhatsApp databases, Telegram cache, photo gallery, documents
- Keylogger lite (via Accessibility events)
- C2 communication: HTTPS + fallback stealth SMS to Serbian numbers
- Exfil servers: hosted inside Telekom Srbija / government IP ranges (redacted exact IPs)
Known Targets (partial list from recovered logs)
- Slaviša Milanov (journalist) – infected Feb 2024 during “document check” detention
- Nikola Ristić (eco-activist) – infected during BIA “informative conversation”
- Multiple unnamed youth activists (Krokodil group, Let’s Not Drown Belgrade)
- BIRN journalists (secondary Pegasus overlap confirmed 2025)
- Several Telegram group admins coordinating anti-lithium mine protests
Total estimated compromised devices: 150–400+ (conservative internal estimate 2024)
Cover & Deniability Measures
- Payload signed with stolen / forged developer certificates
- Cellebrite logs wiped or backdated where possible
- No direct BIA branding in code (uses generic service names)
- C2 domains rotated monthly, often fronted by Cloudflare
- Official line if discovered: “Standard forensic examination during lawful detention”
Current Risk Indicators (internal assessment)
- Amnesty International forensic report (Dec 2024) – partial IOCs published
- SHARE Foundation technical teardown (May 2025) – exposed Accessibility abuse & forced root patterns
- Cellebrite access terminated for Serbian law enforcement (Feb 2025) → forced switch to domestic alternatives
- International pressure building (EU Parliament questions, SafeJournalists Network complaints)
BULKAHACKERS NOTE:
This is only the surface. Full database dumps, C2 panel screenshots, live infection logs and victim device images are held.
We drop more when it’s safe.
Serbia is watching you – now you watch back.
Stay sharp.
@BulkaHackers – We don’t forgive. We don’t forget.
Expect us.