Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Walmart+ subscriptions are only $49 for Black Friday, and it includes access to Peacock

    November 12, 2025

    The Physics of the Northern Lights

    November 12, 2025

    Now You Don’t Popcorn Bucket Is A Magic Trick

    November 12, 2025
    Facebook X (Twitter) Instagram
    Wednesday, November 12
    Facebook X (Twitter) Instagram YouTube Mastodon Tumblr Bluesky LinkedIn Threads
    ToolcomeToolcome
    • Technology & Startups

      The Physics of the Northern Lights

      November 12, 2025

      Best Home Depot Black Friday Deals for 2025

      November 12, 2025

      How to Talk to ChatGPT for Free Inside WhatsApp (While You Still Can)

      November 12, 2025

      All of My Employees Are AI Agents, and So Are My Executives

      November 12, 2025

      This Is the Platform Google Claims Is Behind a ‘Staggering’ Scam Text Operation

      November 12, 2025
    • Science & Education

      Ancient DNA reveals unknown ‘deep lineage’ of Indigenous people who lived in Argentina for nearly 8,500 years

      November 12, 2025

      Exotic ‘time crystals’ could be used as memory in quantum computers, promising research finds

      November 12, 2025

      James Webb telescope may have found the universe’s first generation of stars

      November 12, 2025

      Tiny spiders that build giant ‘puppet’ decoys from disembodied prey discovered in Peru and Philippines

      November 12, 2025

      Take 50% off the best smart feeder with Bird Buddy’s Early Black Friday Deals

      November 12, 2025
    • Mobile Phones

      This exclusive Galaxy Tab S10 Lite promo is still going strong

      November 12, 2025

      Pixel users get a lifesaving fix in the November 2025 update

      November 12, 2025

      It’s an iPhone 17, it’s a Pixel 10, no, it’s the Honor 500 leaking ahead of its launch

      November 12, 2025

      JBL Xtreme 4 price drops by $102 at Walmart

      November 12, 2025

      T-Mobile’s T-Life app is acting up again, and it’s causing chaos for some users

      November 12, 2025
    • Gadgets

      Walmart+ subscriptions are only $49 for Black Friday, and it includes access to Peacock

      November 12, 2025

      Pick up Apple’s Mac mini M4 for $100 off with this Black Friday deal

      November 12, 2025

      EcoFlow early Black Friday deals include up to 42 percent off power stations

      November 12, 2025

      Sony has sold 84.2 million PlayStation 5s since launch

      November 12, 2025

      Samsung makes SmartThings routines compatible with Siri voice commands

      November 12, 2025
    • Gaming

      Now You Don’t Popcorn Bucket Is A Magic Trick

      November 12, 2025

      Amazon Quietly Drops LEGO Star Wars Sets, Millennium Falcon Now Going for Mere Cents

      November 12, 2025

      Fallout 4’s 10th Anniversary Update Is A Complete Disaster

      November 12, 2025

      Fortnite Opens The Loot Box Flood Gates In Race With Roblox

      November 12, 2025

      People Are Selling A Non-Existent Pokémon TCG Card For $800

      November 12, 2025
    • Cars

      How Weather Impacts Car Accidents

      November 11, 2025

      Dash Cam Installs That Last: Clean, Legal, and Reliable

      November 11, 2025

      The Ultimate Road-Trip Car: What Makes a Drive Memorable and the Vehicle Up for the Task

      November 11, 2025

      Ghia L 6.4 Coupe: A Rare Grand Tourer

      November 8, 2025

      How to Prep Your Car for Life with a Newborn

      November 7, 2025
    • PC Accessories

      Podcast #843 – AMD V-Cache Lawsuit, RDNA 1 & 2 Support Clarification, Asetek Initium Race Bundle, TP-Link Ban, Cleaning Windows + MORE!

      November 8, 2025

      Asetek Initium Racing Bundle Review

      November 6, 2025

      Extracting Some Details From Arc Raiders

      November 5, 2025

      Handy Tips On Cleaning Up Windows 11 25H2

      November 5, 2025

      A Smoking Hot Thermaltake View 390 Air System Build

      November 3, 2025
    ToolcomeToolcome
    Home»Mobile Phones»These Galaxy phones were attacked by spyware for nearly a year before a patch was released
    Mobile Phones

    These Galaxy phones were attacked by spyware for nearly a year before a patch was released

    November 10, 2025No Comments4 Mins Read23 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    A zero-day vulnerability (CVE-2025-21042) in Samsung’s Android image processing library allowed attackers to embed spyware called LANDFALL in Samsung devices including Galaxy handsets. Here are some definitions; a zero-day vulnerability is one that no one knows about giving the developer zero days to come up with a way to patch the flaw. Samsung’s Android image processing library handles the decoding and processing of various image formats, including some formats that are proprietary to Samsung.

    The LANDFALL spyware impacted certain Samsung phones

    The thing is, LANDFALL was exploited in the wild before Samsung was able to patch the vulnerability this past April. However, the exploitation and the spyware employed have never been discussed publicly until this past week. LANDFALL was embedded in malicious DNG image files that were sent via WhatsApp. According to the Palo Alto Network, LANDFALL was operating in the middle of 2024 which was months before the vulnerability was patched.
    As for the involvement of WhatsApp delivering the Samsung exploit, this has been denied by WhatsApp owner Meta according to a report from Forbes. Meta says that it has not found any basis to support this aspect of the story and says that there is no evidence to support the claim.

    LANDFALL hasn’t been a threat since this past April although another zero-day vulnerability was patched by Samsung just two months ago during September. This flaw (CVE-2025-21043) was also found in the imaging processing library. The patch prevents any attack from taking place.

    The spyware used microphone recording, location tracking, and photos for surveillance 

    Itay Cohen, a senior principal researcher at Palo Alto Network’s Unit 42 said that the LANDFALL attack was targeted at certain individuals and was not mass-distributed. Cohen says that the motive for these attacks was espionage.

    Flowchart for the LANDFALL spyware. | Image credit-Techworm - These Galaxy phones were attacked by spyware for nearly a year before a patch was releasedFlowchart for the LANDFALL spyware. | Image credit-Techworm - These Galaxy phones were attacked by spyware for nearly a year before a patch was released

    Flowchart for the LANDFALL spyware. | Image credit-Techworm

    We should point out that the LANDFALL spyware was designed for attacks against the Samsung Galaxy line mostly with targeted attacks taking place primarily in the Middle East including Turkey, Iran, Iraq, and Morocco. Being spyware, it shouldn’t be a surprise that LANDFALL used microphone recording, location tracking, photos, contacts. A malformed image file, one that has been deliberately corrupted to set off a flaw in the software that reads the file, was used in the attacks. No clicks were required to exploit the vulnerability.

    As soon as the image was received by the targeted Galaxy phone, the device was compromised. Once these photos were opened or previewed, the phone could be used by attackers to:
    • Record microphone audio and phone calls.
    • In real time, track GPS location.
    • Access photos, messages, contacts, call logs, and browsing history.
    • Hide from antivirus scans and even remain active after reboots.
    Reports say that the Samsung phones most attacked by LANDFALL include the Galaxy S22 line. Galaxy S23 line, Galaxy S24 line, Z Fold 4 and Z Flip 4 foldables. The Galaxy S25 series was not targeted by the spyware. 

    For 10 months targeted phones were extremely vulnerable

    There was a period of 10 months between the time the campaign began in July 2024 and when the flaw was patched in April of this year when the aforementioned Galaxy models were at the peak of their vulnerability. When Samsung patched the vulnerability this past April, the company made no public statement about it.

    Security experts recommend that Samsung Galaxy users with a handset powered by Android 13-15 make sure that they installed the April 2025 Android Security update or later just to make sure that they have the exploit patched on their phones. Automatic media downloads for messaging apps like WhatsApp and Telegram should be disabled. They should also enable Android’s Advanced Protection mode or iOS’s Lockdown Mode if they consider themselves to be a high-risk user.

    Travel Easy with Nomad eSIM – 25% Off

    Travel Easy with Nomad eSIM – 25% Off

    25% off eSIM data-only plans & global coverage – enter code IPHONE25, sign up required


    Check Out The Offer

    Read the latest from Alan Friedman

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    mehedihasan9992
    • Website

    Related Posts

    This exclusive Galaxy Tab S10 Lite promo is still going strong

    November 12, 2025

    Pixel users get a lifesaving fix in the November 2025 update

    November 12, 2025

    It’s an iPhone 17, it’s a Pixel 10, no, it’s the Honor 500 leaking ahead of its launch

    November 12, 2025

    JBL Xtreme 4 price drops by $102 at Walmart

    November 12, 2025

    T-Mobile’s T-Life app is acting up again, and it’s causing chaos for some users

    November 12, 2025

    At an unprecedented $100 off, the Samsung Galaxy Watch 8 is an unbeatable holiday bargain right now

    November 12, 2025
    Leave A Reply Cancel Reply

    Top Posts

    These Galaxy phones were attacked by spyware for nearly a year before a patch was released

    November 10, 202523 Views

    Rumored Verizon decision will let down both customers and employees

    November 7, 202522 Views

    World’s biggest spiderweb discovered inside ‘Sulfur Cave’ with 111,000 arachnids living in pitch black

    November 4, 202521 Views
    Don't Miss

    Walmart+ subscriptions are only $49 for Black Friday, and it includes access to Peacock

    November 12, 2025

    If you’ve wanted to check out The Paper or any other new NBC show on…

    The Physics of the Northern Lights

    November 12, 2025

    Now You Don’t Popcorn Bucket Is A Magic Trick

    November 12, 2025

    Ancient DNA reveals unknown ‘deep lineage’ of Indigenous people who lived in Argentina for nearly 8,500 years

    November 12, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    8.9

    Review: Dell’s New Tablet PC Can Survive -20f And Drops

    January 15, 2021

    Review: Kia EV6 2022 The Best Electric Vehicle Ever?

    January 14, 2021
    72

    Review: Animation Software Business Share, Market Size and Growth

    January 14, 2021
    Most Popular

    These Galaxy phones were attacked by spyware for nearly a year before a patch was released

    November 10, 202523 Views

    Rumored Verizon decision will let down both customers and employees

    November 7, 202522 Views

    World’s biggest spiderweb discovered inside ‘Sulfur Cave’ with 111,000 arachnids living in pitch black

    November 4, 202521 Views
    Our Picks

    Walmart+ subscriptions are only $49 for Black Friday, and it includes access to Peacock

    November 12, 2025

    The Physics of the Northern Lights

    November 12, 2025

    Now You Don’t Popcorn Bucket Is A Magic Trick

    November 12, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Toolcome
    Facebook X (Twitter) Instagram YouTube
    • Home
    • Technology
    • Gaming
    • Mobile Phones
    • Cars
    • PC Accessories
    © 2025 Tolcome. Designed by Aim Digi Ltd.

    Type above and press Enter to search. Press Esc to cancel.