21.1 C
Delhi
Wednesday, March 4, 2026

Samsung Galaxy Spyware Attack via WhatsApp Images Exposed

Key Takeaways

  • Samsung Galaxy phones were targeted by spyware through WhatsApp images for nearly a year
  • Attack exploited CVE-2025-21042 vulnerability in Samsung’s image processing
  • Landfall spyware could access calls, messages, photos, contacts and location data
  • Targeted devices included S22, S23, S24, Z Fold 4 and Z Flip 4 models

A sophisticated spyware campaign targeted Samsung Galaxy phones through seemingly innocent WhatsApp images, operating undetected for almost a year. The attack exploited a critical vulnerability in Samsung’s software that allowed hackers to compromise devices without any user interaction.

The Zero-Click Threat

Security researchers from Palo Alto Networks’ Unit 42 uncovered the operation, which used commercial-grade spyware called Landfall. What made this campaign particularly dangerous was its simplicity – no fake links to click, no suspicious apps to install, just regular-looking images that could completely compromise a device.

The attack relied on a zero-day vulnerability that gave hackers immediate access the moment an image reached the phone. This turned the routine act of receiving photos into a potential surveillance operation.

How the Attack Worked

The vulnerability, tracked as CVE-2025-21042, was hidden in Samsung’s image-processing library. Attackers weaponized Digital Negative (DNG) image files, disguising them as ordinary JPEGs, and delivered them through messaging apps like WhatsApp.

Once inside, Landfall functioned as a comprehensive surveillance tool. It could:

  • Monitor phone calls and record conversations
  • Access photos, messages and contact lists
  • Track the user’s real-time location
  • Scrape sensitive personal data

Targeted Victims and Timeline

The primary targets were Galaxy S22, S23, S24, Z Fold 4, and Z Flip 4 users across Middle Eastern countries including Turkey, Iran, Iraq, and Morocco.

Researchers detected the spyware in mid-2024, but it operated undetected for months. Samsung was informed about the vulnerability in September 2024 but only released a patch in April 2025, leaving devices exposed for approximately seven months.

Espionage Connections

Unit 42 discovered the campaign while analyzing Google’s VirusTotal database, where they found multiple infected DNG files uploaded from the Middle East between 2024 and early 2025.

The digital signatures of Landfall showed similarities to work by Stealth Falcon, a surveillance group previously linked to attacks on journalists and dissidents in the UAE. However, researchers cautioned against definitive attribution due to insufficient evidence.

“It was a precision attack, not a mass campaign,” said Itay Cohen, senior principal researcher at Unit 42. “That strongly suggests espionage motives rather than financial gain.”

Turkey’s national cyber agency confirmed the threat by flagging one of the spyware’s command-and-control servers as malicious, indicating Turkish users were likely among the victims.

Protection and Lessons

Samsung users who have installed recent security updates are now protected against this specific threat. However, the Landfall incident serves as a stark reminder that modern spyware can infiltrate devices without any user action, highlighting the critical importance of and .

Latest

Tony Fadell says iPod is back as users have again started using it

Tony Fadell says the iPod is quietly making a comeback as users rediscover the distraction-free music player. Instead of streaming apps, many are turning to old

Beats launches special MagSafe cases for iPhone 17e, most affordable member of Apple’s iPhone 17 series

As Apple launched the iPhone 17e, Beats has rolled out new cases for the most affordable member of iPhone 17 series, making use of one of its big USP features:

Alibaba launches Qwen 3.5 small model series, beats ChatGPT and Gemini, even Elon Musk is impressed

Alibaba has launched four compact Qwen 3.5 models (0.8B to 9B), claiming the top 9B variant delivers performance close to much larger systems powering tools lik

IPhone 17e launched: India price, full specs, top features and how it compares to iPhone 17

Apple has launched the iPhone 17e in India as the most affordable model in the iPhone 17 line-up, bringing the new A19 chip, a 48MP camera and MagSafe at a lowe

‘Not worth it’: OpenAI scientist slams US Military AI deal as users rush to cancel ChatGPT

OpenAI research scientist Aiden McLaughlin has claimed that the AI startup should not have made the deal with the Pentagon. His comments come at a time when use

Topics

Shreya Ghoshal clarifies she’s not embarrassed about Chikni Chameli amid trolling: ‘I wasn’t mature enough to fully grasp the meaning’

Bollywood playback singer Shreya Ghoshal has addressed the trolling she faced over singing Chikni Chameli from Agneepath, featuring Katrina Kaif. In a.

YouTuber KSI buys Dagenham and Redbridge, shares Premier League vision with fans

International Sports News: It’s official now, KSI has taken over Dagenham and Redbridge. The YouTube star, whose real name is Olajide Olatunji, confirmed he i

Rashee Rice’s life takes a more troubling turn as he makes a concerning post amid an uncertain future with the Kansas City Chiefs

NFL News: Rashee Rice, the Kansas City Chiefs’ star player, has had a difficult few months after his ex girlfriend, Dacoda Jones, about the brutal domestic vi

From UAE to Saudi Arabia, how US-Iran war is affecting the Middle East

Dubai, with a global reputation as the safest place in the Middle East, has sustained damage to its international airport and hotels along its coastline.

Starmer is no Winston Churchill: Trump ups criticism of UK PM over Iran strikes

A diplomatic rift has emerged between Washington and London over UK’s response to US strikes on Iran. The disagreement highlights tensions in US-UK relations

US Consulate on Dubai’s Al Seef Road hit by drone, videos of explosion, fire surface

Videos of explosions at the US Consulate in Dubai circulated on Tuesday. CNN has confirmed it as a “suspected drone attack.”

West Asia crisis: 38 Indian ships stuck in Persian Gulf; 3 sailors dead

Middle East News: NEW DELHI/MUMBAI: Thirty-eight Indian flagged ships, mostly carrying crude and LNG with nearly 1,100 seafarers, were stuck in the Persian Gulf

MLB All Star Jurickson Profar risks full season suspension and 15 million salary after second positive PED test

MLB News: Jurickson Profar is in trouble again. The Atlanta Braves designated hitter has tested positive for performance-enhancing drugs for the second time in
spot_img

Related Articles

Popular Categories

spot_imgspot_img