LEAKED INTERNAL DOC – BULKAHACKERS EXCLUSIVE DROP Classification: HIGHLY CONFIDENTIAL – SERBIAN STATE SURVEILLANCE Source: Alleged internal BIA / MUP forensic & operational materials Leaked by: @BulkaHackers – Preshevo Valley Cyber Crew Date of leak: February 2026 Handle with care – distribution may trigger Article 146 + national security charges OPERATION “DIGITAL CAGE” – NOVISPY DEPLOYMENT OVERVIEW Project codename: NoviSpy / NS-Admin Developer: Internal BIA cyber unit + external contractors (identity redacted) First known build: Q3 2018 Current active version (2025): v4.2.7 (multiple variants generated per target) Deployment window: 2019 – ongoing (peak activity 2023–2025 during environmental & anti-corruption protests) Core objective: Long-term covert monitoring of persons of interest (POI) classified as threats to public order, state stability, or critical infrastructure narratives. Primary targets: journalists, environmental activists, student organizers, NGO staff, protest coordinators, independent media figures. Infection Vector – Physical Access Protocol (Standard Procedure) 1. Subject is brought in for “informal interview”, administrative check, or misdemeanor detention. 2. Device (Android only – iOS not yet supported) handed over or seized temporarily. 3. Cellebrite UFED 4PC / Premier used to: - Bypass lock (known Qualcomm zero-days + brute-force on older models) - Extract full filesystem backup - Install payload without visible traces 4. Two-stage drop: - NoviSpyAdmin (com.serv.services) – main persistence & exfil module - NoviSpyAccess (com.accesibilityservice) – screen/content capture via Accessibility abuse 5. Device returned to subject within 30–90 minutes. Subject usually unaware of compromise. 6. Post-install check: device rebooted, ADB debugging disabled, app hidden from launcher. Active Capabilities – What We Are Pulling (2025 config) - Full screen recording + screenshots (every 5–30 seconds when active) - GPS location logged every 10 minutes (even when GPS “off” via fused location) - Microphone live-stream on demand (up to 48 hours buffered) - Camera snapshots / short clips on trigger - All incoming/outgoing SMS forwarded silently - Call log + contact list exfil - File exfil: WhatsApp databases, Telegram cache, photo gallery, documents - Keylogger lite (via Accessibility events) - C2 communication: HTTPS + fallback stealth SMS to Serbian numbers - Exfil servers: hosted inside Telekom Srbija / government IP ranges (redacted exact IPs) Known Targets (partial list from recovered logs) - Slaviša Milanov (journalist) – infected Feb 2024 during “document check” detention - Nikola Ristić (eco-activist) – infected during BIA “informative conversation” - Multiple unnamed youth activists (Krokodil group, Let’s Not Drown Belgrade) - BIRN journalists (secondary Pegasus overlap confirmed 2025) - Several Telegram group admins coordinating anti-lithium mine protests Total estimated compromised devices: 150–400+ (conservative internal estimate 2024) Cover & Deniability Measures - Payload signed with stolen / forged developer certificates - Cellebrite logs wiped or backdated where possible - No direct BIA branding in code (uses generic service names) - C2 domains rotated monthly, often fronted by Cloudflare - Official line if discovered: “Standard forensic examination during lawful detention” Current Risk Indicators (internal assessment) - Amnesty International forensic report (Dec 2024) – partial IOCs published - SHARE Foundation technical teardown (May 2025) – exposed Accessibility abuse & forced root patterns - Cellebrite access terminated for Serbian law enforcement (Feb 2025) → forced switch to domestic alternatives - International pressure building (EU Parliament questions, SafeJournalists Network complaints) BULKAHACKERS NOTE: This is only the surface. Full database dumps, C2 panel screenshots, live infection logs and victim device images are held. We drop more when it’s safe. Serbia is watching you – now you watch back. Stay sharp. @BulkaHackers – We don’t forgive. We don’t forget. Expect us.