26.8 C
Delhi
Saturday, November 8, 2025

Samsung Galaxy Spyware Attack via WhatsApp Images Exposed

Key Takeaways

  • Samsung Galaxy phones were targeted by spyware through WhatsApp images for nearly a year
  • Attack exploited CVE-2025-21042 vulnerability in Samsung’s image processing
  • Landfall spyware could access calls, messages, photos, contacts and location data
  • Targeted devices included S22, S23, S24, Z Fold 4 and Z Flip 4 models

A sophisticated spyware campaign targeted Samsung Galaxy phones through seemingly innocent WhatsApp images, operating undetected for almost a year. The attack exploited a critical vulnerability in Samsung’s software that allowed hackers to compromise devices without any user interaction.

The Zero-Click Threat

Security researchers from Palo Alto Networks’ Unit 42 uncovered the operation, which used commercial-grade spyware called Landfall. What made this campaign particularly dangerous was its simplicity – no fake links to click, no suspicious apps to install, just regular-looking images that could completely compromise a device.

The attack relied on a zero-day vulnerability that gave hackers immediate access the moment an image reached the phone. This turned the routine act of receiving photos into a potential surveillance operation.

How the Attack Worked

The vulnerability, tracked as CVE-2025-21042, was hidden in Samsung’s image-processing library. Attackers weaponized Digital Negative (DNG) image files, disguising them as ordinary JPEGs, and delivered them through messaging apps like WhatsApp.

Once inside, Landfall functioned as a comprehensive surveillance tool. It could:

  • Monitor phone calls and record conversations
  • Access photos, messages and contact lists
  • Track the user’s real-time location
  • Scrape sensitive personal data

Targeted Victims and Timeline

The primary targets were Galaxy S22, S23, S24, Z Fold 4, and Z Flip 4 users across Middle Eastern countries including Turkey, Iran, Iraq, and Morocco.

Researchers detected the spyware in mid-2024, but it operated undetected for months. Samsung was informed about the vulnerability in September 2024 but only released a patch in April 2025, leaving devices exposed for approximately seven months.

Espionage Connections

Unit 42 discovered the campaign while analyzing Google’s VirusTotal database, where they found multiple infected DNG files uploaded from the Middle East between 2024 and early 2025.

The digital signatures of Landfall showed similarities to work by Stealth Falcon, a surveillance group previously linked to attacks on journalists and dissidents in the UAE. However, researchers cautioned against definitive attribution due to insufficient evidence.

“It was a precision attack, not a mass campaign,” said Itay Cohen, senior principal researcher at Unit 42. “That strongly suggests espionage motives rather than financial gain.”

Turkey’s national cyber agency confirmed the threat by flagging one of the spyware’s command-and-control servers as malicious, indicating Turkish users were likely among the victims.

Protection and Lessons

Samsung users who have installed recent security updates are now protected against this specific threat. However, the Landfall incident serves as a stark reminder that modern spyware can infiltrate devices without any user action, highlighting the critical importance of and .

Latest

Mark Zuckerberg Hires 28-Year-Old Alexandr Wang in $14B AI Deal

Scale AI founder Alexandr Wang appointed to lead Meta's Superintelligence Labs in one of the biggest AI hiring moves of 2025.

OpenAI Sued Over GPT-4o’s Alleged Link to Suicides and Harm

Families sue OpenAI, claiming the premature GPT-4o release contributed to suicides and psychological harm. Learn about the allegations and OpenAI's response.

Google Gemini Creates 8-Second Videos from Text with Sound

Learn how Google Gemini transforms text prompts into animated videos with sound effects and dialogue. Discover subscription options and free access through Jio.

GPS Spoofing Suspected Behind 400 Flight Delays at Delhi Airport

Massive flight disruptions hit Delhi IGI Airport as GPS spoofing and system upgrades create perfect storm for aviation chaos. DGCA launches investigation.

Motorola Edge 50 Pro Price Drops by Rs 14,000 on Amazon Deal

Get the premium Motorola Edge 50 Pro at just Rs 22,999 with massive discounts, 125W charging, and advanced camera system. Limited time offer.

Topics

Delhi Airport Operations Normal After Technical Glitch Disruption

Delhi Airport confirms normal flight operations resume after technical issue affected 800+ flights. Get latest passenger advisory and airline updates.

Mark Zuckerberg Hires 28-Year-Old Alexandr Wang in $14B AI Deal

Scale AI founder Alexandr Wang appointed to lead Meta's Superintelligence Labs in one of the biggest AI hiring moves of 2025.

Tesla Appoints Sharad Agarwal as India Head to Boost Sales

Former Lamborghini India boss Sharad Agarwal takes charge as Tesla aims to overcome slow sales and high import duties in the competitive Indian EV market.

US Layoffs Hit 14-Year High: 1 Million Jobs Cut in 2025

October 2025 saw highest US job cuts since 2003 with 153,074 layoffs. Technology, warehousing sectors lead massive employment downturn affecting nearly 1 million workers.

Pfizer Acquires Metsera in $10 Billion Weight-Loss Drug Deal

Pfizer wins competitive bidding against Novo Nordisk to acquire weight-loss startup Metsera in a landmark $10 billion pharmaceutical acquisition.

HAL Signs $1 Billion Deal with GE for Tejas Jet Engines

HAL secures 113 F404 engines from GE Aerospace for Tejas fighters with deliveries starting 2027, boosting India's indigenous defense capabilities.

OpenAI Sued Over GPT-4o’s Alleged Link to Suicides and Harm

Families sue OpenAI, claiming the premature GPT-4o release contributed to suicides and psychological harm. Learn about the allegations and OpenAI's response.

Blue Origin, FAA Collaborate on New Glenn Rocket Launch for Mars Mission

Blue Origin is working with the FAA to ensure a safe launch of its New Glenn rocket, which will carry the ESCAPADE science mission to the planet Mars.
spot_img

Related Articles

Popular Categories

spot_imgspot_img