Security researchers have found a vulnerability that was used to inject a new spyware called ‘Landfall’ into Samsung Galaxy phones during a hacking campaign that lasted several months, likely aimed at victims in the Middle East.
According to researchers at Unit 42, which is supported by the cybersecurity firm Palo Alto Networks, the attackers took advantage of a security flaw in the Android OS to install the spyware and compromise Galaxy smartphones.
This was a zero-day attack, meaning Samsung was unaware of the vulnerability at that time.
Landfall Spyware
Landfall is a zero-click spyware. This indicates that the spyware could be delivered to target phones without any action needed from the victims.
Just sending a maliciously crafted image to a victim’s phone, probably through a messaging app, could lead to the device being infected by Landfall.
The source code of the spyware identified five Galaxy models as potential targets: the Samsung Galaxy S22, S23, S24, and some Z models.
The researchers also discovered the Android security flaw in other Galaxy devices, noting that devices running Android versions 13 to 15 might also be at risk.
In response, samsung fixed the security flaw that was exploited to deploy the spyware in April of this year.
However, Landfall was first identified in July of last year, and the campaign had been active since mid-2024.
Landfall remained active and undetected for months.
The specific flaw LANDFALL exploited, CVE-2025-21042, is not an isolated incident but part of a larger trend of similar problems found across multiple mobile platforms.
Who Created It?
Landfall can perform extensive surveillance on its victims by collecting on-device data like photos, contacts, and call logs, in addition to accessing the device’s microphone and tracking its exact location.
The spyware is delivered through malformed DNG image files that exploit CVE-2025-21042 – a serious zero-day vulnerability in Samsung’s image processing library, which has been exploited in the wild.
The exact spyware vendor behind Landfall remains unknown.
Landfall was hosted on digital infrastructure similar to a well-known spyware vendor called Stealth Falcon.
Other specifics, like the total number of individuals potentially targeted in this campaign, are still unclear.
For those with Samsung Galaxy S25 Plus and Galaxy S25 Ultra, turning off fast charging might help resolve the issue.
The spyware wasn’t spread out like typical malware. Instead, the attackers executed a “precision attack” targeting specific individuals.
Researchers didn’t have enough proof to definitively say that a government client of Landfall was behind the hacking operation.
- FIFA World Cup 2026: How Fans Can Watch Matches For Free
- YouTube Relaunches Private Chats With Age Verification
- The Future Of Air Travel: Why The 100ml Liquid Limit May Soon Disappear
- Rising Temperatures, Rising Tempers? The Surprising Link Between Heat And Aggression
- India’s Lost Dragonfly Returns After 110 Years
- Snapchat Introduces Safer Story Sharing For Under-16 Users
- Google Launches Gemini 3.5 Live Translate
- The New Dating Trend Everyone’s Talking About: Puffer-Fishing
- Tea, Coffee, Juice: The Worst Empty Stomach Mistakes
- Instagram Introduces Profile Grid Customization
- Skywatchers Alert: Jupiter And Venus Set For A Rare Close Encounter Tonight
- Chrome Just Downloaded a 4GB AI Model? Here’s How to Delete It
- Why Does Real Love Feel Different Than We Expect?
- The 30-Minute Parenting Secret Every Child Needs
- Remote Robotics: Control Robotic Arms From Your Smartphone
- Mumbai’s Pod Taxis: Will BKC Benefit?
- Beyond The Missing Period: Understanding MRKH Syndrome
- Why Calling Every Stomach Problem ‘Gas’ Can Be Risky?
- Poke: Apple’s First AI Agent Debuts
- AC Drying Out Your Skin? Try This Simple Fix
- Want More Fireflies? Transform Your Garden Today
- Spotify Launches Podcast Clips For Instant Highlight Saving
- The Hidden Reason Summer Causes More Headaches
- Early Iron Deficiency Symptoms You Shouldn’t Ignore
- Meta Introduces Premium ‘Plus’ Tier For Instagram, Facebook And WhatsApp
- WhatsApp Launches Channel Status For 24-Hour Admin Updates
- 5 Powerful Signs You’re With The Right Person
- Social Media: The New Smoking For Children?
- Dewy, Glossy, Sweaty: The Viral Makeup Trend Everyone’s Trying
- Luna Launches Smart AI Band For Real-Time Daily Planning
- Meta Launches New ‘Forum’ App
- Why Is Your C-Section Scar Vertical?
- Red vs Orange Heat Alerts: Which One Puts Your Body At Greater Risk?
- Does AC Sleep Weaken Your Immunity? – Myth or Fact?
- The Rise Of Nonnamaxxing
- How To Clean Mushrooms Without Turning Them Soggy?
- How Hot Nights Quietly Harm Your Sleep And Heart?
- Indian Content Creators Can Win a Free Nepal Trip — Here’s How To Apply
- Gemini Omni Flash Brings Multimodal AI Video Creation To Google
- Essential Oil Diffusers: Healthy Trend or Hidden Hazard?
- Gmail Users Alert: Your Free 15 GB Storage Could Disappear
- YouTube Introduces Likeness Detection For 18+ Users
- AI vs Human Language: Is Learning Still Worth It?
- OpenAI Unveils ChatGPT Finance Tools With Direct Bank Integration
- The Ageing Risk Of Sleeping Too Much Or Too Little
- Fitness or Future Pain? The Truth About Joint-Damaging Workouts
- Salt Water Trend: What You Need To Know First?
- X Launches History Tab For Likes, Bookmarks And Videos
- Stay Chill: Smart Gadgets For Summer
- Instagram Launches Instant For Disappearing Photos
- ChatGPT App Now Supports Codex Coding Tool




















































Leave a Reply