Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Former Burnout Devs Are Making A Star Wars Racing Game

    December 12, 2025

    Ars Live: 3 former CDC leaders detail impacts of RFK Jr.’s anti-science agenda

    December 12, 2025

    Legacy of the Dark Knight swoops onto PC and consoles on May 29

    December 12, 2025
    Facebook X (Twitter) Instagram
    Friday, December 12
    Facebook X (Twitter) Instagram YouTube Mastodon Tumblr Bluesky LinkedIn Threads
    ToolcomeToolcome
    • Technology & Startups

      Ars Live: 3 former CDC leaders detail impacts of RFK Jr.’s anti-science agenda

      December 12, 2025

      Disney says Google AI infringes copyright “on a massive scale”

      December 12, 2025

      Supergirl teaser gives us a likably imperfect Kara Zor-El

      December 12, 2025

      OpenAI releases GPT-5.2 after “code red” Google threat alert

      December 12, 2025

      Instead of fixing WoW’s new floating house exploit, Blizzard makes it official

      December 12, 2025
    • Science & Education

      Mosasaurs may have terrorized rivers as well as oceans

      December 12, 2025

      Insomnia and anxiety come with a weaker immune system — a new study starts to unravel why

      December 12, 2025

      Our experts’ top 22 gifts for nature and outdoor lovers

      December 12, 2025

      Pacific Moisture Drenches the U.S. Northwest

      December 12, 2025

      James Webb telescope spots ‘monster stars’ leaking nitrogen in the early universe — and they could help solve a major mystery

      December 12, 2025
    • Mobile Phones

      OnePlus Ace 6T achieves record-breaking first sale performance in China

      December 9, 2025

      Vivo S50 design, four color variants revealed ahead of its official launch

      December 9, 2025

      Polar Loop reinvents wellness tracking without a screen

      December 9, 2025

      Beats Studio Pro Headphones are Available for Just $169 (51% OFF)

      December 9, 2025

      Honor X80 certification confirms extra-large 10,000mAh battery

      December 9, 2025
    • Gadgets

      Legacy of the Dark Knight swoops onto PC and consoles on May 29

      December 12, 2025

      Catalyst and a new remake

      December 12, 2025

      Galactic Racer is a podracing game set for 2026

      December 12, 2025

      Housemarque’s Saros is delayed to April 30

      December 12, 2025

      Everything announced and all the winners at The Game Awards 2025

      December 12, 2025
    • Gaming

      Former Burnout Devs Are Making A Star Wars Racing Game

      December 12, 2025

      Warhammer 40K Brings Grimdark War To The Galaxy

      December 12, 2025

      All The Winners And Losers

      December 12, 2025

      Mega Man Is Alive And Getting A New 2D Sequel In 2027

      December 12, 2025

      Everything We Saw At The 2025 Game Awards

      December 12, 2025
    • Cars

      Best Trucking Dispatch Companies for Owner Operators

      December 10, 2025

      Chelsea Rizzo on the Future of Dealership Marketing

      December 9, 2025

      How Big Trucks Change the Way Enthusiasts Experience the Road

      December 9, 2025

      Some wonderful gift ideas for the car lover

      December 7, 2025

      How AI and Human-Level Lead Nurturing Are Transforming Automotive Advertising — Insights From Thought Leader Chelsea Rizzo of Abundant Auto & AiMom

      December 5, 2025
    • PC Accessories

      Microsoft’s Bounty Program … Improves It’s Scope?

      December 11, 2025

      Time To Dump Windows For Gaming … Or No?

      December 11, 2025

      AMD’s RDNA 4 Cards Get FSR Redstone, Bringing Machine Learning To Upscaling

      December 10, 2025

      AMD Might Extend Life of B650 Chipset – But AM5 Remains a DDR5 Platform

      December 10, 2025

      Like Retrofuturism? Try The HYTE X50

      December 8, 2025
    ToolcomeToolcome
    Home»Mobile Phones»These Galaxy phones were attacked by spyware for nearly a year before a patch was released
    Mobile Phones

    These Galaxy phones were attacked by spyware for nearly a year before a patch was released

    November 10, 2025No Comments4 Mins Read28 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    A zero-day vulnerability (CVE-2025-21042) in Samsung’s Android image processing library allowed attackers to embed spyware called LANDFALL in Samsung devices including Galaxy handsets. Here are some definitions; a zero-day vulnerability is one that no one knows about giving the developer zero days to come up with a way to patch the flaw. Samsung’s Android image processing library handles the decoding and processing of various image formats, including some formats that are proprietary to Samsung.

    The LANDFALL spyware impacted certain Samsung phones

    The thing is, LANDFALL was exploited in the wild before Samsung was able to patch the vulnerability this past April. However, the exploitation and the spyware employed have never been discussed publicly until this past week. LANDFALL was embedded in malicious DNG image files that were sent via WhatsApp. According to the Palo Alto Network, LANDFALL was operating in the middle of 2024 which was months before the vulnerability was patched.
    As for the involvement of WhatsApp delivering the Samsung exploit, this has been denied by WhatsApp owner Meta according to a report from Forbes. Meta says that it has not found any basis to support this aspect of the story and says that there is no evidence to support the claim.

    LANDFALL hasn’t been a threat since this past April although another zero-day vulnerability was patched by Samsung just two months ago during September. This flaw (CVE-2025-21043) was also found in the imaging processing library. The patch prevents any attack from taking place.

    The spyware used microphone recording, location tracking, and photos for surveillance 

    Itay Cohen, a senior principal researcher at Palo Alto Network’s Unit 42 said that the LANDFALL attack was targeted at certain individuals and was not mass-distributed. Cohen says that the motive for these attacks was espionage.

    Flowchart for the LANDFALL spyware. | Image credit-Techworm - These Galaxy phones were attacked by spyware for nearly a year before a patch was releasedFlowchart for the LANDFALL spyware. | Image credit-Techworm - These Galaxy phones were attacked by spyware for nearly a year before a patch was released

    Flowchart for the LANDFALL spyware. | Image credit-Techworm

    We should point out that the LANDFALL spyware was designed for attacks against the Samsung Galaxy line mostly with targeted attacks taking place primarily in the Middle East including Turkey, Iran, Iraq, and Morocco. Being spyware, it shouldn’t be a surprise that LANDFALL used microphone recording, location tracking, photos, contacts. A malformed image file, one that has been deliberately corrupted to set off a flaw in the software that reads the file, was used in the attacks. No clicks were required to exploit the vulnerability.

    As soon as the image was received by the targeted Galaxy phone, the device was compromised. Once these photos were opened or previewed, the phone could be used by attackers to:
    • Record microphone audio and phone calls.
    • In real time, track GPS location.
    • Access photos, messages, contacts, call logs, and browsing history.
    • Hide from antivirus scans and even remain active after reboots.
    Reports say that the Samsung phones most attacked by LANDFALL include the Galaxy S22 line. Galaxy S23 line, Galaxy S24 line, Z Fold 4 and Z Flip 4 foldables. The Galaxy S25 series was not targeted by the spyware. 

    For 10 months targeted phones were extremely vulnerable

    There was a period of 10 months between the time the campaign began in July 2024 and when the flaw was patched in April of this year when the aforementioned Galaxy models were at the peak of their vulnerability. When Samsung patched the vulnerability this past April, the company made no public statement about it.

    Security experts recommend that Samsung Galaxy users with a handset powered by Android 13-15 make sure that they installed the April 2025 Android Security update or later just to make sure that they have the exploit patched on their phones. Automatic media downloads for messaging apps like WhatsApp and Telegram should be disabled. They should also enable Android’s Advanced Protection mode or iOS’s Lockdown Mode if they consider themselves to be a high-risk user.

    Travel Easy with Nomad eSIM – 25% Off

    Travel Easy with Nomad eSIM – 25% Off

    25% off eSIM data-only plans & global coverage – enter code IPHONE25, sign up required


    Check Out The Offer

    Read the latest from Alan Friedman

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    mehedihasan9992
    • Website

    Related Posts

    OnePlus Ace 6T achieves record-breaking first sale performance in China

    December 9, 2025

    Vivo S50 design, four color variants revealed ahead of its official launch

    December 9, 2025

    Polar Loop reinvents wellness tracking without a screen

    December 9, 2025

    Beats Studio Pro Headphones are Available for Just $169 (51% OFF)

    December 9, 2025

    Honor X80 certification confirms extra-large 10,000mAh battery

    December 9, 2025

    One UI 8.5 full changelog leaks ahead of beta rollout on Galaxy S25 series

    December 9, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Black Friday Disney+, Hulu and ESPN streaming deal: Up to 44% off

    November 30, 202540 Views

    These Galaxy phones were attacked by spyware for nearly a year before a patch was released

    November 10, 202528 Views

    Rumored Verizon decision will let down both customers and employees

    November 7, 202527 Views
    Don't Miss

    Former Burnout Devs Are Making A Star Wars Racing Game

    December 12, 2025

    A second Star Wars game was announced at the Game Awards 2025, but this is…

    Ars Live: 3 former CDC leaders detail impacts of RFK Jr.’s anti-science agenda

    December 12, 2025

    Legacy of the Dark Knight swoops onto PC and consoles on May 29

    December 12, 2025

    Mosasaurs may have terrorized rivers as well as oceans

    December 12, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    8.9

    Review: Dell’s New Tablet PC Can Survive -20f And Drops

    January 15, 2021

    Review: Kia EV6 2022 The Best Electric Vehicle Ever?

    January 14, 2021
    72

    Review: Animation Software Business Share, Market Size and Growth

    January 14, 2021
    Most Popular

    Black Friday Disney+, Hulu and ESPN streaming deal: Up to 44% off

    November 30, 202540 Views

    These Galaxy phones were attacked by spyware for nearly a year before a patch was released

    November 10, 202528 Views

    Rumored Verizon decision will let down both customers and employees

    November 7, 202527 Views
    Our Picks

    Former Burnout Devs Are Making A Star Wars Racing Game

    December 12, 2025

    Ars Live: 3 former CDC leaders detail impacts of RFK Jr.’s anti-science agenda

    December 12, 2025

    Legacy of the Dark Knight swoops onto PC and consoles on May 29

    December 12, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Toolcome
    Facebook X (Twitter) Instagram YouTube Mastodon Bluesky
    • Home
    • Technology
    • Gaming
    • Mobile Phones
    • Cars
    • PC Accessories
    © 2025 Tolcome.

    Type above and press Enter to search. Press Esc to cancel.