• News/
  • https://www.theregister.com/2025/11/07/landfall_spyware_samsung_0days/

Previously unknown Landfall spyware used in 0-day attacks on Samsung phones

The Register
·
Jessica Lyons
·
Published Nov 7, 2025
·
Updated

A previously unknown Android spyware family called LANDFALL exploited a zero-day in Samsung Galaxy devices for nearly a year, installing surveillance code capable of recording calls, tracking locations, and harvesting photos and logs before Samsung finally patched it in April. The surveillance campaign likely began in July 2024 and abused CVE-2025-21042, a critical bug in Samsung's image-processing library that affects Galaxy devices running Android versions 13, 14, 15, and 16, according to Palo Alto Networks Unit 42 researchers who discovered the commercial-grade spyware and revealed details of the espionage attacks in a Friday report. "This was a precision espionage campaign, targeting specific Samsung Galaxy devices in the Middle East, with likely victims in Iraq, Iran, Turkey, and Morocco," Itay Cohen, a senior principal researcher at Unit 42, told The Register. "The use of zero-day exploits, custom infrastructure, and modular payload design all indicate an espionage-motivated operation." According to the cyber sleuths, exploiting CVE-2025-21042 likely involved sending a maliciously crafted image to the victim's device via a messaging application in a "zero-click" attack, meaning that infecting targeted phones didn't require any user interaction. "It's not clear exactly how many people were targeted or exploited, but in a recent, related campaign, involving iOS and WhatsApp, WhatsApp shared that less than 200 were targeted in that campaign, so we can reasonably expect thi...

Read full article

Affected Software

4 affected components
Samsung Galaxy=13
Samsung Galaxy=14
Samsung Galaxy=15
Samsung Galaxy=16

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the discovery of a new spyware called Landfall that exploits zero-day vulnerabilities in Samsung Galaxy devices.

2

What security implications are discussed?

The article highlights the risks posed by Landfall spyware, including its ability to record calls, track locations, and harvest photos from compromised devices.

3

What products or software are affected?

The affected products include Samsung Galaxy devices, specifically versions 13, 14, 15, and 16.

4

How long was the Landfall spyware active before it was discovered?

The spyware was actively exploiting vulnerabilities in Samsung Galaxy devices for nearly a year before its discovery.

5

What types of surveillance capabilities does the Landfall spyware have?

Landfall spyware is capable of recording phone calls, tracking user locations, and harvesting images from compromised devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203