27.1 C
Delhi
Sunday, November 9, 2025

Samsung Galaxy Spyware Attack via WhatsApp Images Exposed

Key Takeaways

  • A spyware campaign exploited a Samsung software flaw via weaponized DNG images sent through WhatsApp.
  • The “Landfall” spyware could infect devices without user interaction (zero-click attack).
  • Affected models include Galaxy S22, S23, S24, Z Fold 4, and Z Flip 4.
  • Samsung patched the vulnerability in April 2025 after months of exposure.

A sophisticated spyware campaign has been targeting Samsung Galaxy smartphones through a critical vulnerability in the device’s image-processing software. The attack, which required no user interaction beyond receiving a message, allowed hackers to install commercial-grade spyware simply by sending a weaponized image file.

What is the Landfall Spyware?

Security researchers from Palo Alto Networks’ Unit 42 uncovered a spyware operation that remained active for nearly a year. The campaign exploited a flaw in Samsung’s software to infiltrate phones without requiring victims to click any links or install suspicious apps.

The hackers used a commercial spyware called “Landfall,” which they concealed within seemingly harmless photos distributed through popular messaging applications like WhatsApp.

How the Attack Works

The vulnerability, tracked as CVE-2025-21042, existed in Samsung’s image-processing library. Attackers weaponized Digital Negative (DNG) image files, disguising them as ordinary JPEGs, and delivered them through messaging platforms.

This constituted a “zero-click” attack where simply receiving the image could silently compromise the device. Users wouldn’t need to download, open, or interact with the file for the infection to occur.

Spyware Capabilities and Targets

Once installed, Landfall functioned as a comprehensive surveillance tool capable of:

  • Monitoring all phone calls and recording conversations
  • Accessing photos, messages, and contact lists
  • Tracking the user’s location in real-time
  • Scouring through personal data and communications

The primary targets included users of Galaxy S22, S23, S24, Z Fold 4, and Z Flip 4 models across several Middle Eastern countries, particularly Turkey, Iran, Iraq, and Morocco.

Timeline of the Vulnerability

Researchers first detected the spyware campaign in mid-2024, though it had been operating undetected for months prior. Samsung was notified about the security issue in September 2024 but didn’t release a patch until April 2025.

This nearly seven-month gap left numerous devices vulnerable to silent surveillance despite the company’s awareness of the threat.

Protection and Recommendations

Samsung users who have installed the April 2025 security update are now protected against this specific vulnerability. However, the Landfall incident serves as a stark reminder about the evolving nature of mobile threats.

Security experts recommend:

  • Avoid downloading media files from unknown contacts on messaging apps
  • Regularly install the latest security patch updates
  • Be cautious of any unsolicited images, even from known contacts
  • Enable automatic security updates when available

Latest

IIT Grads Raise $61M for AI Startup Giga, Face Racist Attacks

Indian engineers Varun Vammadi and Esha Maindeep secured major funding for their AI startup but encountered racist comments online after their success announcement.

Google Maps Gets Gemini AI Update in India: 6 Key Features

Google Maps now integrates Gemini AI for hands-free navigation, real-time traffic alerts, and enhanced road safety features designed specifically for Indian users.

Nvidia CEO Asks TSMC for More Wafers as AI Demand Surges

Jensen Huang requests additional chip supplies from TSMC as AI hardware demand grows monthly, highlighting semiconductor industry capacity constraints.

OnePlus 15 India Launch Date: Snapdragon 8 Elite, 165Hz Display, Price

OnePlus 15 launches November 13 with Snapdragon 8 Elite Gen 5, 165Hz LTPO display, 7300mAh battery, and 120W charging. Expected price ₹65,000-70,000.

Samsung Galaxy S24 Ultra ₹50,000 Off on Flipkart – Limited Time Deal

Save up to ₹50,000 on Samsung Galaxy S24 Ultra 5G with Flipkart discounts, bank offers and exchange deals. Get the flagship smartphone at 36% off original price.

Topics

RBI Allows Loans Against Silver Jewellery and Coins From April 2026

Get loans up to 85% against silver jewellery value. New RBI guidelines make silver assets loan-eligible through banks from 2026.

InCred Holdings Files Confidential IPO Papers for ₹3,000–4,000 Crore Issue

InCred Holdings confidentially files for massive IPO with Sebi. Discover FY25 financial results, lending portfolio details, and confidential filing benefits.

IIT Grads Raise $61M for AI Startup Giga, Face Racist Attacks

Indian engineers Varun Vammadi and Esha Maindeep secured major funding for their AI startup but encountered racist comments online after their success announcement.

Tsunami Warning Issued After 6.7 Magnitude Earthquake Hits Japan

Japan issues tsunami advisory after major 6.7 earthquake strikes northern Pacific waters, with waves expected along Iwate coastline.

Google Maps Gets Gemini AI Update in India: 6 Key Features

Google Maps now integrates Gemini AI for hands-free navigation, real-time traffic alerts, and enhanced road safety features designed specifically for Indian users.

India’s Forex Reserves Drop to $689.7 Billion, Near Record High

India's forex reserves fell by $5.6 billion but remain close to record $704.9 billion. RBI maintains strong import coverage of 11+ months.

Credit Card Spending Surges 23% to Rs 2.17 Lakh Crore in September

India's credit card spending hits record Rs 2.17 lakh crore with 23% YoY growth. Discover key trends in card issuances, market share shifts, and spending patterns.

Offal Bolognese: Scientists Say Eating Organs Could Save Planet

Research shows offal-enriched meals reduce environmental impact while providing nutrient-rich, affordable protein options for British consumers.
spot_img

Related Articles

Popular Categories

spot_imgspot_img