16.1 C
Delhi
Wednesday, March 4, 2026

Samsung Galaxy Spyware Attack: LANDFALL Targeted Users for Months

Key Takeaways

  • Samsung Galaxy devices were targeted by ‘LANDFALL’ spyware via malicious DNG image files
  • The spyware exploited zero-day vulnerabilities to access photos, contacts, call logs, and record audio
  • Primary targets were users in Middle Eastern countries including Iraq, Iran, Turkey, and Morocco
  • Samsung released security patches in April and September 2025 to address the vulnerabilities

Samsung Galaxy users faced a sophisticated spyware campaign that exploited critical vulnerabilities in Android’s image processing system. The ‘LANDFALL’ spyware, discovered by researchers, allowed hackers to infiltrate devices without user interaction through malicious image files.

Zero-Day Vulnerability Exploited

According to Unit 42 research, the LANDFALL spyware leveraged a zero-day flaw identified as CVE-2025-21042 in Samsung’s Android image processing library. The malware was concealed within Digital Negative (DNG) file formats – a type of raw image format based on TIFF.

The campaign remained active from mid-2024 until Samsung addressed the vulnerability through firmware updates in April 2025. A related security flaw, CVE-2025-21043, was subsequently patched in September 2025 to prevent similar attacks.

Spyware Capabilities and Targets

LANDFALL functioned as modular spyware specifically designed for Samsung Galaxy devices. Between July 2024 and February 2025, multiple malicious DNG files containing the spyware were identified online.

The malware provided attackers with extensive surveillance capabilities including:

  • Secret audio recording
  • Location tracking
  • Access to personal photos, contacts, and call logs

Affected device models included Samsung Galaxy S22, S23 Series, S24 Series, Z Fold 4, and Z Flip 4. The campaign primarily targeted users in Middle Eastern nations such as Iraq, Iran, Turkey, and Morocco.

Detection and Response Timeline

Researchers first reported the issue to Samsung in September 2024. The company responded with security patches in April 2025, followed by additional fixes in September 2025 for the related CVE-2025-21043 vulnerability identified by WhatsApp researchers.

Mobile security experts note that sophisticated malware like LANDFALL typically relies on multiple vulnerability chains to fully compromise devices.

Latest

Is there still a way for Anthropic to ‘go back’ to the US government, FCC chief Brendan Carr answers

Tech News News: Artificial Intelligence company Anthropic has been banned by the US government. Claude-maker Anthropic was blacklisted on Friday, February 28, a

OpenAI is changing its contract with Pentagon; CEO Sam Altman says: I would rather go to jail than…

Mobiles & Tablets News: OpenAI is amending its freshly signed deal with the US Department of Defense after fierce public blowback over whether the agreement act

OpenAI loses 1.5 million subscribers in less than 48 hours after CEO Sam Altman says yes to the deal that Anthropic rejected

Tech News News: Sam Altman-led OpenAI is facing a backlash after agreeing to let the US Department of Defense use its AI models on a classified government netwo

How Anthropic vs. Pentagon puts billions at ‘risk’ for Nvidia

Tech News News: Nvidia has spent the last two years minting money as the arms dealer of the AI boom—selling chips to everyone, picking sides with no one. That

Facebook-parent Meta takes on ChatGPT and Google Gemini with another AI feature

Tech News News: Meta is quietly testing a new AI-powered shopping feature, putting itself in a direct competition with ChatGPT and Google Gemini, which are alre

Topics

Love Horoscope Today for March 4, 2026: Commitment talks could shift your equation

Daily Love Horoscope March 4, 2026: Find daily astrological predictions for all sun signs.

Is Reddit down? Thousands report report issues amid widespread outages

Reddit suffered an outage Tuesday afternoon, with thousands of users across the United States reporting issues, according to Down Detector.

Trump shares important message for US citizens in Middle East amid Operation Epic Fury, ‘If you want to come home…’

Donald Trump has shared an important note for US citizens in the Middle East, telling them how the State Department will help them if they want to return home.

Macron sends aircraft carrier Charles de Gaulle to Mediterranean amid Iran war

President Emmanuel Macron ordered France’s aircraft carrier Charles de Gaulle to the Mediterranean, deployed jets and air defenses, and said French forces sho

NYC’s First Lady Rama Duwaji shares artwork in support of detained activist

NYC’s First Lady Rama Duwaji shared artwork in support of detained Palestinian woman Leqaa Kordia.

US service members killed in Iranian drone strike ID’d: Who were Cody Khork, Noah Tietjens, Nicole Amor & Declan Coady?

The four US service members who were killed by an Iranian drone strike during Operation Epic Fury have been identified.

Trump ‘rash’: New photos spark cover-up allegations amid health concerns about POTUS; ‘so apparent’

President Donald Trump was photographed with what appeared to be a reddish rash on the side of his neck, while at the recent Medal of Honor event.

Liverpool rocked by last-gasp defeat at Wolves

Liverpool rocked by last-gasp defeat at Wolves
spot_img

Related Articles

Popular Categories

spot_imgspot_img