18.1 C
Delhi
Friday, January 16, 2026

Samsung Galaxy Spyware Attack via WhatsApp Images Exposed

Key Takeaways

  • Samsung Galaxy phones were targeted by spyware through WhatsApp images for nearly a year
  • Attack exploited CVE-2025-21042 vulnerability in Samsung’s image processing
  • Landfall spyware could access calls, messages, photos, contacts and location data
  • Targeted devices included S22, S23, S24, Z Fold 4 and Z Flip 4 models

A sophisticated spyware campaign targeted Samsung Galaxy phones through seemingly innocent WhatsApp images, operating undetected for almost a year. The attack exploited a critical vulnerability in Samsung’s software that allowed hackers to compromise devices without any user interaction.

The Zero-Click Threat

Security researchers from Palo Alto Networks’ Unit 42 uncovered the operation, which used commercial-grade spyware called Landfall. What made this campaign particularly dangerous was its simplicity – no fake links to click, no suspicious apps to install, just regular-looking images that could completely compromise a device.

The attack relied on a zero-day vulnerability that gave hackers immediate access the moment an image reached the phone. This turned the routine act of receiving photos into a potential surveillance operation.

How the Attack Worked

The vulnerability, tracked as CVE-2025-21042, was hidden in Samsung’s image-processing library. Attackers weaponized Digital Negative (DNG) image files, disguising them as ordinary JPEGs, and delivered them through messaging apps like WhatsApp.

Once inside, Landfall functioned as a comprehensive surveillance tool. It could:

  • Monitor phone calls and record conversations
  • Access photos, messages and contact lists
  • Track the user’s real-time location
  • Scrape sensitive personal data

Targeted Victims and Timeline

The primary targets were Galaxy S22, S23, S24, Z Fold 4, and Z Flip 4 users across Middle Eastern countries including Turkey, Iran, Iraq, and Morocco.

Researchers detected the spyware in mid-2024, but it operated undetected for months. Samsung was informed about the vulnerability in September 2024 but only released a patch in April 2025, leaving devices exposed for approximately seven months.

Espionage Connections

Unit 42 discovered the campaign while analyzing Google’s VirusTotal database, where they found multiple infected DNG files uploaded from the Middle East between 2024 and early 2025.

The digital signatures of Landfall showed similarities to work by Stealth Falcon, a surveillance group previously linked to attacks on journalists and dissidents in the UAE. However, researchers cautioned against definitive attribution due to insufficient evidence.

“It was a precision attack, not a mass campaign,” said Itay Cohen, senior principal researcher at Unit 42. “That strongly suggests espionage motives rather than financial gain.”

Turkey’s national cyber agency confirmed the threat by flagging one of the spyware’s command-and-control servers as malicious, indicating Turkish users were likely among the victims.

Protection and Lessons

Samsung users who have installed recent security updates are now protected against this specific threat. However, the Landfall incident serves as a stark reminder that modern spyware can infiltrate devices without any user action, highlighting the critical importance of and .

Latest

India’s Scramjet Success: Why Fighter Jets Still Use Conventional Engines

India joins the hypersonic club with scramjet tech. We explain why this breakthrough won't power fighter jets yet and what it means for missiles and space travel.

Meta Bans ChatGPT on WhatsApp from 2026: How to Save Chats

WhatsApp will block ChatGPT and third-party AI tools in 2026. Learn why Meta is banning AI, how to back up your chat history, and what it means for users.

Amazon Republic Day Sale 2026: Up to 80% Off on Gadgets & Appliances

Amazon's Great Republic Day Sale 2026 is live with massive discounts on electronics, fashion & home appliances. Get top deals, no-cost EMI & a chance to win a trip.

Amazon Republic Day Sale: iPhone 15, OnePlus Nord 5, iQOO 15 Big Discounts

Get record-low prices on iPhone 15, OnePlus Nord 5, and iQOO 15 during Amazon's Great Republic Day Sale 2025 from Jan 14-18. Details on discounts, bank offers, and early access.

CERT-In Flags High-Risk Dolby Bug on Android, Urges Patch

Indian cybersecurity agency warns of a critical Dolby Audio vulnerability in Android 13/14. Learn how to protect your device with the latest security update.

Topics

Doctor’s Viral Senate Testimony: “Biologically, Men Cannot Get Pregnant”

Dr Nisha Verma's exchange with a US senator on pregnancy and gender terminology goes viral, highlighting post-Roe reproductive rights debates.

Trump Nominated for Nobel Peace Prize Over Abraham Accords Role

US lawmaker nominates Donald Trump for the Nobel Peace Prize, citing his historic role in brokering the Abraham Accords. This marks his fourth nomination.

US Lawmaker Calls Pakistan a Failed State, Contrasts with India

Congressman Rich McCormick's speech contrasts India's investment role with Pakistan, which he accuses of harbouring terrorism and being a Chinese client state.

UGC Proposes 1 Counsellor per 500 Students, Mental Health Centres in Colleges

New UGC draft mandates mental health centres & a fixed counsellor ratio in all Indian colleges to support student well-being and equitable opportunity.

Why Pune is Called the Research Capital of India

Discover how Pune's unique ecosystem of top universities, national labs, and industry R&D earned it the title of India's research capital.

China’s Top Universities Outrank Harvard in Global Research Output

Nature Index 2024 reveals Chinese universities surpass Harvard in research share, signaling a major shift in global science leadership driven by decades of investment.

Michael Bloomberg Warns White House Fed Attacks Are Dangerous Overreach

Billionaire Michael Bloomberg says White House criticism of the Federal Reserve threatens economic stability, could trigger recession, and must stop.

India-Germany Trade Hits €30 Billion: A Strategic Partnership Evolves

Record trade sets the stage for deeper India-Germany collaboration in green tech, AI, and resilient supply chains as global dynamics shift.
spot_img

Related Articles

Popular Categories

spot_imgspot_img