Samsung Galaxy Spyware Attack via WhatsApp Images Exposed

Key Takeaways

  • A spyware campaign exploited a Samsung software flaw via weaponized DNG images sent through WhatsApp.
  • The “Landfall” spyware could infect devices without user interaction (zero-click attack).
  • Affected models include Galaxy S22, S23, S24, Z Fold 4, and Z Flip 4.
  • Samsung patched the vulnerability in April 2025 after months of exposure.

A sophisticated spyware campaign has been targeting Samsung Galaxy smartphones through a critical vulnerability in the device’s image-processing software. The attack, which required no user interaction beyond receiving a message, allowed hackers to install commercial-grade spyware simply by sending a weaponized image file.

What is the Landfall Spyware?

Security researchers from Palo Alto Networks’ Unit 42 uncovered a spyware operation that remained active for nearly a year. The campaign exploited a flaw in Samsung’s software to infiltrate phones without requiring victims to click any links or install suspicious apps.

The hackers used a commercial spyware called “Landfall,” which they concealed within seemingly harmless photos distributed through popular messaging applications like WhatsApp.

How the Attack Works

The vulnerability, tracked as CVE-2025-21042, existed in Samsung’s image-processing library. Attackers weaponized Digital Negative (DNG) image files, disguising them as ordinary JPEGs, and delivered them through messaging platforms.

This constituted a “zero-click” attack where simply receiving the image could silently compromise the device. Users wouldn’t need to download, open, or interact with the file for the infection to occur.

Spyware Capabilities and Targets

Once installed, Landfall functioned as a comprehensive surveillance tool capable of:

  • Monitoring all phone calls and recording conversations
  • Accessing photos, messages, and contact lists
  • Tracking the user’s location in real-time
  • Scouring through personal data and communications

The primary targets included users of Galaxy S22, S23, S24, Z Fold 4, and Z Flip 4 models across several Middle Eastern countries, particularly Turkey, Iran, Iraq, and Morocco.

Timeline of the Vulnerability

Researchers first detected the spyware campaign in mid-2024, though it had been operating undetected for months prior. Samsung was notified about the security issue in September 2024 but didn’t release a patch until April 2025.

This nearly seven-month gap left numerous devices vulnerable to silent surveillance despite the company’s awareness of the threat.

Protection and Recommendations

Samsung users who have installed the April 2025 security update are now protected against this specific vulnerability. However, the Landfall incident serves as a stark reminder about the evolving nature of mobile threats.

Security experts recommend:

  • Avoid downloading media files from unknown contacts on messaging apps
  • Regularly install the latest security patch updates
  • Be cautious of any unsolicited images, even from known contacts
  • Enable automatic security updates when available

Latest

AI transforming journalism; women journos can turn tech shift into opportunities: Brijesh Singh

AI transforming journalism; women journos can turn tech shift into opportunities: Brijesh Singh

Indian-origin iLearning execs held in US over fake AI revenue fraud case

Two Indian-origin executives, Puthugramam “Harish” Chidambaran and Sayyed Farhan Ali “Farhan” Naqvi have been accused of running a multi-year fraud with

After Nord 6, OnePlus to launch Nord CE 6 and CE 6 Lite in India, key specs revealed

OnePlus Nord CE6 series is set to launch on May 7 in the Indian market. The lineup consists of two smartphones, the OnePlus Nord CE6 and the OnePlus Nord CE6 Li

I integrated Google Gemini into my daily workflow and saw real productivity gains

From email drafts to task management, I integrated Google Gemini into my daily workflow to test if it actually saves time. Here’s what worked, what didn’t,

OnePlus Nord CE 6, Nord CE 6 Lite India launch date confirmed, battery, chipset and display details revealed

OnePlus has confirmed that the Nord CE 6 and Nord CE 6 Lite will debut in India on 7 May at 12noon. The Oppo sub-brand has also confirmed many key specs of the

Topics

Two Southwest Airlines planes came dangerously close in Nashville and had to take evasive action

Two Southwest Airlines planes came dangerously close in Nashville and had to take evasive action

I’m winning war by a lot: Trump claims amid uncertainty over Iran talks in Pakistan

US-Iran negotiations in Pakistan uncertain as Trump makes bold claims

Proud of myself: Tilak rejoices after maiden IPL hundred ends MI’s wait for victory

IPL 2026, GT vs MI: Tilak Varma smashed a brilliant unbeaten 101 off 45 balls to power Mumbai Indians to a 99-run win over Gujarat Titans and match MI’s faste

Not Hardik Pandya’s problem: MI captain hits back at critics over Bumrah first-over call

IPL 2026, GT vs MI: Back to winning ways after four defeats in a row, a relieved Mumbai Indians skipper Hardik Pandya took a dig at critics who had questioned h

Rick Perry’s Fermi Is Undermining the AI Energy Thesis

The Fermi Paradox asks why, given the vastness of the universe, there is no hard evidence of aliens. The Fermi Inc. paradox asks why, given seemingly insatiable

Digital Gold explained: Here’s all you need to know about cost, associated charges, risk and tax liability for the asset

If your investment in gold is not for personal use, there are other alternatives to choose when looking to invest in the asset instead of purchasing physical go

CBI arrests two RCOM senior officials in bank ‘fraud’ case

The two executives were important functionaries of the Reliance Communications group, managing corporate finance, banking operations, payments/utilisation of fu
spot_img

Related Articles

Popular Categories

spot_imgspot_img