Samsung Galaxy Spyware Attack: LANDFALL Targeted Users for Months

Key Takeaways

  • Samsung Galaxy devices were targeted by ‘LANDFALL’ spyware via malicious DNG image files
  • The spyware exploited zero-day vulnerabilities to access photos, contacts, call logs, and record audio
  • Primary targets were users in Middle Eastern countries including Iraq, Iran, Turkey, and Morocco
  • Samsung released security patches in April and September 2025 to address the vulnerabilities

Samsung Galaxy users faced a sophisticated spyware campaign that exploited critical vulnerabilities in Android’s image processing system. The ‘LANDFALL’ spyware, discovered by researchers, allowed hackers to infiltrate devices without user interaction through malicious image files.

Zero-Day Vulnerability Exploited

According to Unit 42 research, the LANDFALL spyware leveraged a zero-day flaw identified as CVE-2025-21042 in Samsung’s Android image processing library. The malware was concealed within Digital Negative (DNG) file formats – a type of raw image format based on TIFF.

The campaign remained active from mid-2024 until Samsung addressed the vulnerability through firmware updates in April 2025. A related security flaw, CVE-2025-21043, was subsequently patched in September 2025 to prevent similar attacks.

Spyware Capabilities and Targets

LANDFALL functioned as modular spyware specifically designed for Samsung Galaxy devices. Between July 2024 and February 2025, multiple malicious DNG files containing the spyware were identified online.

The malware provided attackers with extensive surveillance capabilities including:

  • Secret audio recording
  • Location tracking
  • Access to personal photos, contacts, and call logs

Affected device models included Samsung Galaxy S22, S23 Series, S24 Series, Z Fold 4, and Z Flip 4. The campaign primarily targeted users in Middle Eastern nations such as Iraq, Iran, Turkey, and Morocco.

Detection and Response Timeline

Researchers first reported the issue to Samsung in September 2024. The company responded with security patches in April 2025, followed by additional fixes in September 2025 for the related CVE-2025-21043 vulnerability identified by WhatsApp researchers.

Mobile security experts note that sophisticated malware like LANDFALL typically relies on multiple vulnerability chains to fully compromise devices.

Latest

Tim Cook stepping down as CEO but will continue to work for Apple, here is what he will do

Tim Cook to leave CEO post, yet continues with Apple

RIP Tim Apple, Silicon Valley reacts as Tim Cook steps down as CEO

Apple has announced that Tim Cook will be stepping down from his role of CEO after 15 years at the helm. Cook’s departure has been met with reactions from the

Who is new Apple CEO John Ternus? 25 years in one place and blank LinkedIn profile, he is insider

Apple CEO Tim Cook is stepping down. He will be succeeded by John Ternus, the chief of hardware engineering at Apple. This marks the biggest leadership shift at

End of an era: Tim Cook steps down as Apple CEO, read his full letter to the community here

Apple CEO Tim Cook has announced that he is stepping down from his role at the Cupertino giant after almost 15 years at the helm. Cook wrote a letter to the App

Apple names John Ternus as next CEO as Tim Cook shifts role

Apple shifts focus to AI and hardware with new CEO

Topics

No IIT pressure from parents: Chandigarh teen bags AIR 8 in JEE, aims IIT Bombay

Chandigarh student Aarush Singhal secured AIR 8 in JEE Main 2026 with a perfect 100 percentile, inspiring aspirants across India. From disciplined study habits

Delhi HC bars Law Prep from using CLAT AIR 1 identity, orders content removal

A legal dispute over credit, reputation, and digital content in the competitive CLAT coaching space has reached the Delhi High Court. The case brings into focus

Groww shares hit 52-week high: What’s driving the rally and should you buy now?

Groww shares soar to new heights, but brokerages offer mixed advice

School timings revised across states due to heatwave, check the list here

School timings have been revised in Uttar Pradesh due to rising heatwave conditions along with other states such as Madhya Pradesh, Kerala and more. New morning

RIP Tim Apple, Silicon Valley reacts as Tim Cook steps down as CEO

Apple has announced that Tim Cook will be stepping down from his role of CEO after 15 years at the helm. Cook’s departure has been met with reactions from the

Kollywood vs Kollywood: Stars don political greasepaint to eclipse star candidates

Kollywood stars take centre stage in Tamil Nadu's political arena

Study Ayurveda in India: Scholarships open for foreign students till May 15

India has invited foreign students to apply for AYUSH scholarships by May 15, 2026. The programme offers funded degrees in Ayurveda, Yoga and traditional medici
spot_img

Related Articles

Popular Categories

spot_imgspot_img