26.1 C
Delhi
Saturday, November 8, 2025

Samsung Galaxy Spyware Attack via WhatsApp Images Exposed

Key Takeaways

  • Samsung Galaxy phones were targeted by spyware through WhatsApp images for nearly a year
  • Attack exploited CVE-2025-21042 vulnerability in Samsung’s image processing
  • Landfall spyware could access calls, messages, photos, contacts and location data
  • Targeted devices included S22, S23, S24, Z Fold 4 and Z Flip 4 models

A sophisticated spyware campaign targeted Samsung Galaxy phones through seemingly innocent WhatsApp images, operating undetected for almost a year. The attack exploited a critical vulnerability in Samsung’s software that allowed hackers to compromise devices without any user interaction.

The Zero-Click Threat

Security researchers from Palo Alto Networks’ Unit 42 uncovered the operation, which used commercial-grade spyware called Landfall. What made this campaign particularly dangerous was its simplicity – no fake links to click, no suspicious apps to install, just regular-looking images that could completely compromise a device.

The attack relied on a zero-day vulnerability that gave hackers immediate access the moment an image reached the phone. This turned the routine act of receiving photos into a potential surveillance operation.

How the Attack Worked

The vulnerability, tracked as CVE-2025-21042, was hidden in Samsung’s image-processing library. Attackers weaponized Digital Negative (DNG) image files, disguising them as ordinary JPEGs, and delivered them through messaging apps like WhatsApp.

Once inside, Landfall functioned as a comprehensive surveillance tool. It could:

  • Monitor phone calls and record conversations
  • Access photos, messages and contact lists
  • Track the user’s real-time location
  • Scrape sensitive personal data

Targeted Victims and Timeline

The primary targets were Galaxy S22, S23, S24, Z Fold 4, and Z Flip 4 users across Middle Eastern countries including Turkey, Iran, Iraq, and Morocco.

Researchers detected the spyware in mid-2024, but it operated undetected for months. Samsung was informed about the vulnerability in September 2024 but only released a patch in April 2025, leaving devices exposed for approximately seven months.

Espionage Connections

Unit 42 discovered the campaign while analyzing Google’s VirusTotal database, where they found multiple infected DNG files uploaded from the Middle East between 2024 and early 2025.

The digital signatures of Landfall showed similarities to work by Stealth Falcon, a surveillance group previously linked to attacks on journalists and dissidents in the UAE. However, researchers cautioned against definitive attribution due to insufficient evidence.

“It was a precision attack, not a mass campaign,” said Itay Cohen, senior principal researcher at Unit 42. “That strongly suggests espionage motives rather than financial gain.”

Turkey’s national cyber agency confirmed the threat by flagging one of the spyware’s command-and-control servers as malicious, indicating Turkish users were likely among the victims.

Protection and Lessons

Samsung users who have installed recent security updates are now protected against this specific threat. However, the Landfall incident serves as a stark reminder that modern spyware can infiltrate devices without any user action, highlighting the critical importance of and .

Latest

Government Launches Global AI Contest for Women with ₹25 Lakh Prize

Apply for the AI by HER Global Impact Challenge. Women innovators can win ₹25 lakh and mentorship for deployable AI solutions in agriculture, healthcare, and more.

Mark Zuckerberg Hires 28-Year-Old Alexandr Wang in $14B AI Deal

Scale AI founder Alexandr Wang appointed to lead Meta's Superintelligence Labs in one of the biggest AI hiring moves of 2025.

Indian Government Warns of Critical Chrome Security Flaws

Update Chrome immediately: Indian authorities alert users about high-risk vulnerabilities that could allow attackers to take control of your computer.

OpenAI Sued Over GPT-4o’s Alleged Link to Suicides and Harm

Families sue OpenAI, claiming the premature GPT-4o release contributed to suicides and psychological harm. Learn about the allegations and OpenAI's response.

Google Gemini Creates 8-Second Videos from Text with Sound

Learn how Google Gemini transforms text prompts into animated videos with sound effects and dialogue. Discover subscription options and free access through Jio.

Topics

Government Launches Global AI Contest for Women with ₹25 Lakh Prize

Apply for the AI by HER Global Impact Challenge. Women innovators can win ₹25 lakh and mentorship for deployable AI solutions in agriculture, healthcare, and more.

Delhi Airport Operations Normal After Technical Glitch Disruption

Delhi Airport confirms normal flight operations resume after technical issue affected 800+ flights. Get latest passenger advisory and airline updates.

Mark Zuckerberg Hires 28-Year-Old Alexandr Wang in $14B AI Deal

Scale AI founder Alexandr Wang appointed to lead Meta's Superintelligence Labs in one of the biggest AI hiring moves of 2025.

Tesla Appoints Sharad Agarwal as India Head to Boost Sales

Former Lamborghini India boss Sharad Agarwal takes charge as Tesla aims to overcome slow sales and high import duties in the competitive Indian EV market.

Think Investments Puts ₹136 Crore in PhysicsWallah Ahead of IPO

Global firm acquires stake from employees at premium price as edtech unicorn prepares for ₹3,480 crore public offering next week.

US Layoffs Hit 14-Year High: 1 Million Jobs Cut in 2025

October 2025 saw highest US job cuts since 2003 with 153,074 layoffs. Technology, warehousing sectors lead massive employment downturn affecting nearly 1 million workers.

Pfizer Acquires Metsera in $10 Billion Weight-Loss Drug Deal

Pfizer wins competitive bidding against Novo Nordisk to acquire weight-loss startup Metsera in a landmark $10 billion pharmaceutical acquisition.

HAL Signs $1 Billion Deal with GE for Tejas Jet Engines

HAL secures 113 F404 engines from GE Aerospace for Tejas fighters with deliveries starting 2027, boosting India's indigenous defense capabilities.
spot_img

Related Articles

Popular Categories

spot_imgspot_img