20.1 C
Delhi
Monday, November 10, 2025

Samsung Galaxy Spyware Attack: LANDFALL Targeted Users for Months

Key Takeaways

  • Samsung Galaxy devices were targeted by ‘LANDFALL’ spyware via malicious DNG image files
  • The spyware exploited zero-day vulnerabilities to access photos, contacts, call logs, and record audio
  • Primary targets were users in Middle Eastern countries including Iraq, Iran, Turkey, and Morocco
  • Samsung released security patches in April and September 2025 to address the vulnerabilities

Samsung Galaxy users faced a sophisticated spyware campaign that exploited critical vulnerabilities in Android’s image processing system. The ‘LANDFALL’ spyware, discovered by researchers, allowed hackers to infiltrate devices without user interaction through malicious image files.

Zero-Day Vulnerability Exploited

According to Unit 42 research, the LANDFALL spyware leveraged a zero-day flaw identified as CVE-2025-21042 in Samsung’s Android image processing library. The malware was concealed within Digital Negative (DNG) file formats – a type of raw image format based on TIFF.

The campaign remained active from mid-2024 until Samsung addressed the vulnerability through firmware updates in April 2025. A related security flaw, CVE-2025-21043, was subsequently patched in September 2025 to prevent similar attacks.

Spyware Capabilities and Targets

LANDFALL functioned as modular spyware specifically designed for Samsung Galaxy devices. Between July 2024 and February 2025, multiple malicious DNG files containing the spyware were identified online.

The malware provided attackers with extensive surveillance capabilities including:

  • Secret audio recording
  • Location tracking
  • Access to personal photos, contacts, and call logs

Affected device models included Samsung Galaxy S22, S23 Series, S24 Series, Z Fold 4, and Z Flip 4. The campaign primarily targeted users in Middle Eastern nations such as Iraq, Iran, Turkey, and Morocco.

Detection and Response Timeline

Researchers first reported the issue to Samsung in September 2024. The company responded with security patches in April 2025, followed by additional fixes in September 2025 for the related CVE-2025-21043 vulnerability identified by WhatsApp researchers.

Mobile security experts note that sophisticated malware like LANDFALL typically relies on multiple vulnerability chains to fully compromise devices.

Latest

TRAI Overhauls Nine Telecom Interconnection Regulations for 5G Era

India's telecom regulator launches comprehensive review of interconnection rules to modernize framework for 4G/5G networks and satellite communications.

Elon Musk: Tesla Optimus Robots Will End Poverty and Crime

Elon Musk reveals how Tesla's Optimus humanoid robots could eliminate poverty, prevent crime, and transform the global economy after securing $1 trillion pay package.

DeepSeek Researcher: AI Could Eliminate All Human Jobs in 10 Years

Senior DeepSeek researcher warns AI may take over all human jobs within a decade, urging tech companies to become guardians against massive societal challenges.

Software Engineer Salaries in India: Bengaluru Pays 4X More Than Ahmedabad

New data reveals Bengaluru software engineers earn ₹34.98 lakh average salary while Ahmedabad pays just ₹8.97 lakh. See complete city-wise breakdown and key insights.

ISRO Advances Joint Satellite Project with Mauritius in Bilateral Visit

ISRO delegation visits Mauritius for joint satellite development, technical sessions with MRIC, and climate monitoring initiatives to strengthen bilateral space cooperation.

Topics

Canada Increases Off-Campus Work Hours for International Students to 24

International students in Canada can now work 24 hours weekly off-campus starting November 2024, while facing stricter visa norms and reduced intake targets.

TRAI Overhauls Nine Telecom Interconnection Regulations for 5G Era

India's telecom regulator launches comprehensive review of interconnection rules to modernize framework for 4G/5G networks and satellite communications.

Electric Cooking Could Save Indian Households 37% on Fuel Costs: IEEFA

New study reveals electric cooking is cheaper than LPG and PNG, offering sustainable solution for India's clean energy transition and reducing import dependency.

Chinese Biotech Claims Anti-Aging Pill Could Extend Lifespan to 150

Lonvi Biosciences says its grapeseed extract pills target zombie cells and could make 150-year lifespans reality within years. Learn about the science and expert opinion.

Elon Musk: Tesla Optimus Robots Will End Poverty and Crime

Elon Musk reveals how Tesla's Optimus humanoid robots could eliminate poverty, prevent crime, and transform the global economy after securing $1 trillion pay package.

DeepSeek Researcher: AI Could Eliminate All Human Jobs in 10 Years

Senior DeepSeek researcher warns AI may take over all human jobs within a decade, urging tech companies to become guardians against massive societal challenges.

Vodafone Idea Raises Rs 1,999 Plan to Rs 2,249 with Extra Data

Vi increases annual prepaid plan price by Rs 250 but adds 4-6GB extra data. Compare circle-wise benefits and see how it stacks against Airtel.

Software Engineer Salaries in India: Bengaluru Pays 4X More Than Ahmedabad

New data reveals Bengaluru software engineers earn ₹34.98 lakh average salary while Ahmedabad pays just ₹8.97 lakh. See complete city-wise breakdown and key insights.
spot_img

Related Articles

Popular Categories

spot_imgspot_img