A previously unknown Android spyware family called LANDFALL exploited a zero-day in Samsung Galaxy devices for nearly a year, installing surveillance code capable of recording calls, tracking locations, and harvesting photos and logs before Samsung finally patched it in April. The surveillance campaign likely began in July 2024 and abused CVE-2025-21042, a critical bug in Samsung's image-processing library that affects Galaxy devices running Android versions 13, 14, 15, and 16, according to Palo Alto Networks Unit 42 researchers who discovered the commercial-grade spyware and revealed details of the espionage attacks in a Friday report. "This was a precision espionage campaign, targeting specific Samsung Galaxy devices in the Middle East, with likely victims in Iraq, Iran, Turkey, and Morocco," Itay Cohen, a senior principal researcher at Unit 42, told The Register. "The use of zero-day exploits, custom infrastructure, and modular payload design all indicate an espionage-motivated operation." According to the cyber sleuths, exploiting CVE-2025-21042 likely involved sending a maliciously crafted image to the victim's device via a messaging application in a "zero-click" attack, meaning that infecting targeted phones didn't require any user interaction. "It's not clear exactly how many people were targeted or exploited, but in a recent, related campaign, involving iOS and WhatsApp, WhatsApp shared that less than 200 were targeted in that campaign, so we can reasonably expect thi...
Previously unknown Landfall spyware used in 0-day attacks on Samsung phones
The Register
·Jessica Lyons
·Published Nov 7, 2025
·Updated
Affected Software
4 affected components
Samsung Galaxy=13
Samsung Galaxy=14
Samsung Galaxy=15
Samsung Galaxy=16
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the discovery of a new spyware called Landfall that exploits zero-day vulnerabilities in Samsung Galaxy devices.
2
What security implications are discussed?
The article highlights the risks posed by Landfall spyware, including its ability to record calls, track locations, and harvest photos from compromised devices.
3
What products or software are affected?
The affected products include Samsung Galaxy devices, specifically versions 13, 14, 15, and 16.
4
How long was the Landfall spyware active before it was discovered?
The spyware was actively exploiting vulnerabilities in Samsung Galaxy devices for nearly a year before its discovery.
5
What types of surveillance capabilities does the Landfall spyware have?
Landfall spyware is capable of recording phone calls, tracking user locations, and harvesting images from compromised devices.