Samsung Galaxy Spyware Attack: LANDFALL Targeted Users for Months

Key Takeaways

  • Samsung Galaxy devices were targeted by ‘LANDFALL’ spyware via malicious DNG image files
  • The spyware exploited zero-day vulnerabilities to access photos, contacts, call logs, and record audio
  • Primary targets were users in Middle Eastern countries including Iraq, Iran, Turkey, and Morocco
  • Samsung released security patches in April and September 2025 to address the vulnerabilities

Samsung Galaxy users faced a sophisticated spyware campaign that exploited critical vulnerabilities in Android’s image processing system. The ‘LANDFALL’ spyware, discovered by researchers, allowed hackers to infiltrate devices without user interaction through malicious image files.

Zero-Day Vulnerability Exploited

According to Unit 42 research, the LANDFALL spyware leveraged a zero-day flaw identified as CVE-2025-21042 in Samsung’s Android image processing library. The malware was concealed within Digital Negative (DNG) file formats – a type of raw image format based on TIFF.

The campaign remained active from mid-2024 until Samsung addressed the vulnerability through firmware updates in April 2025. A related security flaw, CVE-2025-21043, was subsequently patched in September 2025 to prevent similar attacks.

Spyware Capabilities and Targets

LANDFALL functioned as modular spyware specifically designed for Samsung Galaxy devices. Between July 2024 and February 2025, multiple malicious DNG files containing the spyware were identified online.

The malware provided attackers with extensive surveillance capabilities including:

  • Secret audio recording
  • Location tracking
  • Access to personal photos, contacts, and call logs

Affected device models included Samsung Galaxy S22, S23 Series, S24 Series, Z Fold 4, and Z Flip 4. The campaign primarily targeted users in Middle Eastern nations such as Iraq, Iran, Turkey, and Morocco.

Detection and Response Timeline

Researchers first reported the issue to Samsung in September 2024. The company responded with security patches in April 2025, followed by additional fixes in September 2025 for the related CVE-2025-21043 vulnerability identified by WhatsApp researchers.

Mobile security experts note that sophisticated malware like LANDFALL typically relies on multiple vulnerability chains to fully compromise devices.

Latest

End of an era: Tim Cook steps down as Apple CEO, read his full letter to the community here

Apple CEO Tim Cook has announced that he is stepping down from his role at the Cupertino giant after almost 15 years at the helm. Cook wrote a letter to the App

Apple names John Ternus as next CEO as Tim Cook shifts role

Apple shifts focus to AI and hardware with new CEO

AI transforming journalism; women journos can turn tech shift into opportunities: Brijesh Singh

AI transforming journalism; women journos can turn tech shift into opportunities: Brijesh Singh

Atlan engineers banned from coding, only allowed to teach AI, says founder Prukalpa Sankar

Atlan is shifting towards an AI-first approach. The company’s founder has asked its employees to train AI systems instead of directly executing tasks.

Cursor, which is replacing humans with autonomous AI systems, now asking Elon Musk for help

Elon Musk's expertise is sought as AI replaces human roles

Topics

Apple shares rise 1% after Tim Cook exit, John Ternus named CEO

Tim Cook exits as CEO, John Ternus steps up to lead Apple

End of an era: Tim Cook steps down as Apple CEO, read his full letter to the community here

Apple CEO Tim Cook has announced that he is stepping down from his role at the Cupertino giant after almost 15 years at the helm. Cook wrote a letter to the App

Who is John Ternus, the man set to replace Tim Cook at Apple

A fresh era for Apple as John Ternus takes over from Tim Cook

Migrant workers return to Bengal to protect their mandate amid SIR fears

People will vote to elect representatives for the 294 seats of the West Bengal Assembly in two phases on April 23 and 29. The results will be announced on May 4

Quote of the Day by Dhirubhai Ambani: If you don’t build your dream…

Powerful words by Dhirubhai Ambani inspire millions to take control of their future and pursue their own vision. His mindset of dreaming big and creating opport

Why did DA increase by only 2% this time? Here’s the real reason

The latest DA hike has come in at just 2%, leaving many employees surprised. With expectations going up to 4%, why did the increase stay at the lower end?

Apple names John Ternus as next CEO as Tim Cook shifts role

Apple shifts focus to AI and hardware with new CEO

Two Southwest Airlines planes came dangerously close in Nashville and had to take evasive action

Two Southwest Airlines planes came dangerously close in Nashville and had to take evasive action
spot_img

Related Articles

Popular Categories

spot_imgspot_img