Samsung Galaxy Smartphones Targeted By Spyware Landfall for Over a Year

Once activated, the spyware Landfall can record audio, read messages, and copy data without detection.

Advertisement
Written by Akash Dutta, Edited by Ketan Pratap | Updated: 11 November 2025 12:05 IST
Highlights
  • The spyware is said to be targeting specific Samsung Galaxy phones
  • It exploited a flaw in the phone’s photo library’s image processing
  • The vulnerability was tracked as CVE-2025-21042

Samsung patched the vulnerability in April

Samsung Galaxy smartphones were reportedly vulnerable to a new Android Spyware dubbed Landfall for more than a year. As per the report, the malware can be spread via seemingly normal images shared over social media apps, and targeted image parsing in the device's library. The report mentions that it is a commercial-grade malware that specifically focuses on a zero-day vulnerability on specific Galaxy models. The South Korean tech giant addressed the flaw earlier this year, but the spyware was reportedly active for more than 12 months before that.

Landfall Spyware Targets Samsung Galaxy Phones

The sophisticated spyware attack was first uncovered by cybersecurity researchers at Unit 42, the threat intelligence arm of Palo Alto Networks. The spyware was found hidden inside image files and used an unpatched vulnerability to secretly take control of affected devices.

At the heart of the attack was a zero-day vulnerability in Samsung's image-processing library. A zero-day refers to a security flaw that the manufacturer is not yet aware of, leaving users defenceless until a patch is released. In this case, the bug allowed attackers to embed malicious code inside DNG image files, a format commonly used by professional cameras for storing raw photos.

Advertisement

To break it down, all it requires to get infected with the malware is to receive a message. It can be downloaded from an app, received via email, or shared in a group on an instant messaging platform. As soon as the image has been downloaded on the device, the attack begins. The image file secretly carries a trapdoor that, when opened by your phone's image viewer, installs a hidden spy programme in the background. That's essentially how Landfall worked.

Advertisement

Once triggered, the spyware unpacked two hidden components: one acted as a loader to start the infection, while the other tampered with the phone's SELinux policy, a key Android security feature that controls what apps can and cannot do. By altering it, the spyware gave itself elevated permissions to record audio, read messages, and copy data without detection.

The malware was mainly found targeting Samsung Galaxy S22, Galaxy S23, and Galaxy S24 series, as well as the Z Fold 4 and Z Flip 4 models. Unit 42's analysis of uploaded samples suggests that the campaign may have begun in mid-2024 and continued into early 2025 before it was exposed. Most of the affected devices appeared to be in the Middle East, including Iraq, Iran, Turkey, and Morocco.

Advertisement

Samsung patched the exploited vulnerability, tracked as CVE-2025-21042, in its April security update. A related image-processing flaw, CVE-2025-21043, was also fixed in September. Users who have not updated their phones since early this year are urged to do so immediately.

 
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Compact design
  • Vibrant 120Hz display
  • Capable processor
  • Good overall camera performance
  • Bad
  • Average battery life
  • Recycled design
  • AI features free till 2025
 
KEY SPECS
Display 6.20-inch
Processor octa-core
Front Camera 12-megapixel
Rear Camera 50-megapixel + 12-megapixel + 10-megapixel
RAM 8GB
Storage 128GB, 256GB, 512GB
Battery Capacity 4000mAh
OS Android 14
NEWS
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Compact design that?s hard to beat
  • Long-term software update commitment
  • Good performance, effective heat management
  • All-day battery life
  • IP68 rated
  • Bad
  • Only minor design changes
  • Relatively slow charging
 
KEY SPECS
Display 6.10-inch
Processor Snapdragon 8 Gen 2
Front Camera 12-megapixel
Rear Camera 50-megapixel + 12-megapixel + 10-megapixel
RAM 8GB
Storage 128GB, 256GB
Battery Capacity 3,900mAh
OS Android 13
NEWS

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Asus Tipped to Start RAM Manufacturing Amid Global Shortage
  2. iQOO Z11 Turbo Confirmed to Pack Snapdragon 8 Gen 5 SoC at This Price
  3. WhatsApp for iOS May Soon Make It Simple for Admins to Grow Their Audience
  4. Realme 16 Pro Will Launch in India With This MediaTek Chip, Battery
  5. Stranger Things Season 5 Volume 2 Now Streaming on Netflix: What You Need to Know
  6. Possible Motorola Edge 70 Ultra Spotted on 3C Database With 90W Support
  7. Xiaomi Buds 6 With Harman-Tuned Audio Launched at This Price
  8. OnePlus Turbo Series Will Launch Soon; Now Available for Pre-Order
  9. Poco M8 5G Design, Camera Details Teased Ahead of India Launch
  10. OnePlus Turbo Live Images Reveal Design, Key Specs Ahead of Launch
  1. Samsung to Reportedly Start Manufacturing Its Next-Gen AI Memory Chip in 2026
  2. BMSG FES’25 – GRAND CHAMP Concert Film Now Streaming on Amazon Prime Video
  3. Bridgerton Season 4 OTT Release Date: When and Where to Watch it Online?
  4. Nvidia Is Reportedly Acquiring AI Chip Designer Groq’s Assets for $20 Billion
  5. Samsung’s Galaxy Z TriFold Display Breaks in Bend Test, Raising Durability Concerns
  6. iQOO Z11 Turbo Price, Chipset, More Details Revealed Ahead of Launch: See Expected Features
  7. Disco Elysium - The Final Cut Is Free Right Now on Epic Games Store: How to Redeem
  8. Google’s NotebookLM to Reportedly Add a Lecture Mode to Audio Overviews; Teases New British Accent
  9. Honor Power 2 Spotted on Geekbench With MediaTek Dimensity 8500 SoC; iPhone Pro-Like Design Leaks
  10. Lenovo Watch GT Pro Launched With 1.43-Inch Display, SpO2 Monitor: Price, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.