Skip to main content
See every side of every news story
Published loading...Updated

Commercial Spyware “Landfall” Ran Rampant on Samsung Phones for Almost a Year

Landfall spyware exploited a zero-day flaw in Samsung Galaxy phones to conduct targeted surveillance in the Middle East over nearly a year, researchers said.

  • On Friday, Palo Alto Networks Unit 42 revealed LandFall, a spyware targeting Samsung Galaxy devices in the Middle East that was active since at least July 2024 before being patched this year.
  • Researchers found the campaign abused CVE-2025-21042, a critical out-of-bounds write in libimagecodec.quram.so triggered by malicious DNG image files, enabling zero-click infection via WhatsApp since July 23, 2024.
  • Unit 42's analysis shows LandFall targets five Galaxy models including Galaxy S22, S23, S24, Z Fold 4 and Z Flip 4, embedding a loader and SELinux policy manipulator while using six command-and-control servers.
  • Unit 42 cautioned that although Landfall shares infrastructure similarities with Stealth Falcon, attribution remains unclear as `The technical overlaps are intriguing but not strong enough for responsible attribution`, Cohen said, and researchers urged users to install this year's patch due to removal difficulty.
  • Related patches and advisories show that Unit 42 noted LandFall's DNG-image technique echoes broader DNG image-parsing exploitation observed in recent commercial spyware operations, with similarities to activity in August and September, Cohen said.
Insights by Ground AI

13 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Palo Alto Networks broke the news in on Friday, November 7, 2025.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal