Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Reid Hoffman Wants Silicon Valley to ‘Stand Up’ Against the Trump Administration

    January 13, 2026

    Smartphone Camera Scores Explained: Are DxOMark Rankings Really Reliable?

    January 13, 2026

    Samsung Pushes Galaxy Watch 8 (2025) to Its Lowest Price in New Year Clearance, While Apple Watches Stay Full Price

    January 13, 2026
    Facebook X (Twitter) Instagram
    Thursday, January 15
    Facebook X (Twitter) Instagram YouTube Mastodon Tumblr Bluesky LinkedIn Threads
    ToolcomeToolcome
    • Technology & Startups

      Reid Hoffman Wants Silicon Valley to ‘Stand Up’ Against the Trump Administration

      January 13, 2026

      Urevo SpaceWalk 5L Walking Pad Review: Compact and Affordable

      January 13, 2026

      Board Review: Tabletop Video Games With Physical Pieces

      January 13, 2026

      Atonemo Streamplayer Review: Make Old Speakers New Again

      January 13, 2026

      What to Do If ICE Invades Your Neighborhood

      January 13, 2026
    • Science & Education

      Hubble Nets Menagerie of Young Stellar Objects

      January 13, 2026

      Ötzi the Iceman mummy carried a high-risk strain of HPV, research finds

      January 13, 2026

      Can you eat too much protein?

      January 13, 2026

      NASA’s Webb Delivers Unprecedented Look Into Heart of Circinus Galaxy

      January 13, 2026

      Backcountry is blowing out hiking bags, backpacks, and luggage for up to 65% off during this clearance sale

      January 13, 2026
    • Mobile Phones

      Smartphone Camera Scores Explained: Are DxOMark Rankings Really Reliable?

      January 13, 2026

      Motorola expands Android 16 beta program to 8 more devices

      January 13, 2026

      Motorola Introduces Moto Pen Ultra for Foldables and Moto Tag 2 Item Tracker

      January 13, 2026

      OnePlus Nord CE 5 Update Adds Video Editing Tools and January Security Patch

      January 13, 2026

      Vivo rolls out OriginOS 6 (Android 16) update to Vivo V40

      January 13, 2026
    • Gadgets

      Star Wars Outlaws developer Massive Entertainment and Ubisoft Stockholm face layoffs

      January 13, 2026

      Insta360 releases AI-powered follow-up to its Link webcams

      January 13, 2026

      Proton’s Lumo AI chatbot now has an encrypted space for your projects

      January 13, 2026

      The best streaming devices for 2026

      January 13, 2026

      UK regulator Ofcom opens a formal investigation into X over CSAM scandal

      January 13, 2026
    • Gaming

      Samsung Pushes Galaxy Watch 8 (2025) to Its Lowest Price in New Year Clearance, While Apple Watches Stay Full Price

      January 13, 2026

      ASUS ROG Xbox Ally (2025 Ryzen Z2 A) Just Hit Its Lowest Price Ever With 3 Months of Game Pass Included

      January 13, 2026

      Samsung Goes All-In on Galaxy S25 Ultra Clearance at a Record Low as the New S26 Launch Approaches

      January 13, 2026

      This Great Switch 2 Handheld Controller Is On Sale For New Best Price At Amazon

      January 13, 2026

      Google Pixel 9a Drops to All-Time Low to Compete With Samsung Galaxy S25 Deals, Now the Cheapest Gemini-Powered Smartphone

      January 13, 2026
    • Cars

      Beyond Speed: A Deep Dive into the 6 Safety Features That Could Save Your Supercar in 2026

      January 13, 2026

      A Commercial Truck Caused a Hit-and-Run: Who Pays for the Damage?

      January 13, 2026

      Risk and reward: what driving teaches about smart decisions

      January 13, 2026

      How It’s Played Online on GameZone

      January 12, 2026

      How Dubai Became the Supercar Capital of the World

      January 12, 2026
    • PC Accessories

      A Kilowatt PSU Is So 2025, The Seasonic Prime PX-2200 Is The Future

      January 12, 2026

      CES 2026: The Good, Bad And Ugly

      January 12, 2026

      Hands-On With Samsung Galaxy Z TriFold: An Impressive New Take On Foldables

      January 11, 2026

      Edifier’s Funky Portable ES300 Wireless Speaker

      January 9, 2026

      Testing All The Features of AMD’s FSR Redstone

      January 9, 2026
    ToolcomeToolcome
    Home»Mobile Phones»These Galaxy phones were attacked by spyware for nearly a year before a patch was released
    Mobile Phones

    These Galaxy phones were attacked by spyware for nearly a year before a patch was released

    November 10, 2025No Comments4 Mins Read28 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    A zero-day vulnerability (CVE-2025-21042) in Samsung’s Android image processing library allowed attackers to embed spyware called LANDFALL in Samsung devices including Galaxy handsets. Here are some definitions; a zero-day vulnerability is one that no one knows about giving the developer zero days to come up with a way to patch the flaw. Samsung’s Android image processing library handles the decoding and processing of various image formats, including some formats that are proprietary to Samsung.

    The LANDFALL spyware impacted certain Samsung phones

    The thing is, LANDFALL was exploited in the wild before Samsung was able to patch the vulnerability this past April. However, the exploitation and the spyware employed have never been discussed publicly until this past week. LANDFALL was embedded in malicious DNG image files that were sent via WhatsApp. According to the Palo Alto Network, LANDFALL was operating in the middle of 2024 which was months before the vulnerability was patched.
    As for the involvement of WhatsApp delivering the Samsung exploit, this has been denied by WhatsApp owner Meta according to a report from Forbes. Meta says that it has not found any basis to support this aspect of the story and says that there is no evidence to support the claim.

    LANDFALL hasn’t been a threat since this past April although another zero-day vulnerability was patched by Samsung just two months ago during September. This flaw (CVE-2025-21043) was also found in the imaging processing library. The patch prevents any attack from taking place.

    The spyware used microphone recording, location tracking, and photos for surveillance 

    Itay Cohen, a senior principal researcher at Palo Alto Network’s Unit 42 said that the LANDFALL attack was targeted at certain individuals and was not mass-distributed. Cohen says that the motive for these attacks was espionage.

    Flowchart for the LANDFALL spyware. | Image credit-Techworm - These Galaxy phones were attacked by spyware for nearly a year before a patch was releasedFlowchart for the LANDFALL spyware. | Image credit-Techworm - These Galaxy phones were attacked by spyware for nearly a year before a patch was released

    Flowchart for the LANDFALL spyware. | Image credit-Techworm

    We should point out that the LANDFALL spyware was designed for attacks against the Samsung Galaxy line mostly with targeted attacks taking place primarily in the Middle East including Turkey, Iran, Iraq, and Morocco. Being spyware, it shouldn’t be a surprise that LANDFALL used microphone recording, location tracking, photos, contacts. A malformed image file, one that has been deliberately corrupted to set off a flaw in the software that reads the file, was used in the attacks. No clicks were required to exploit the vulnerability.

    As soon as the image was received by the targeted Galaxy phone, the device was compromised. Once these photos were opened or previewed, the phone could be used by attackers to:
    • Record microphone audio and phone calls.
    • In real time, track GPS location.
    • Access photos, messages, contacts, call logs, and browsing history.
    • Hide from antivirus scans and even remain active after reboots.
    Reports say that the Samsung phones most attacked by LANDFALL include the Galaxy S22 line. Galaxy S23 line, Galaxy S24 line, Z Fold 4 and Z Flip 4 foldables. The Galaxy S25 series was not targeted by the spyware. 

    For 10 months targeted phones were extremely vulnerable

    There was a period of 10 months between the time the campaign began in July 2024 and when the flaw was patched in April of this year when the aforementioned Galaxy models were at the peak of their vulnerability. When Samsung patched the vulnerability this past April, the company made no public statement about it.

    Security experts recommend that Samsung Galaxy users with a handset powered by Android 13-15 make sure that they installed the April 2025 Android Security update or later just to make sure that they have the exploit patched on their phones. Automatic media downloads for messaging apps like WhatsApp and Telegram should be disabled. They should also enable Android’s Advanced Protection mode or iOS’s Lockdown Mode if they consider themselves to be a high-risk user.

    Travel Easy with Nomad eSIM – 25% Off

    Travel Easy with Nomad eSIM – 25% Off

    25% off eSIM data-only plans & global coverage – enter code IPHONE25, sign up required


    Check Out The Offer

    Read the latest from Alan Friedman

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    mehedihasan9992
    • Website

    Related Posts

    Smartphone Camera Scores Explained: Are DxOMark Rankings Really Reliable?

    January 13, 2026

    Motorola expands Android 16 beta program to 8 more devices

    January 13, 2026

    Motorola Introduces Moto Pen Ultra for Foldables and Moto Tag 2 Item Tracker

    January 13, 2026

    OnePlus Nord CE 5 Update Adds Video Editing Tools and January Security Patch

    January 13, 2026

    Vivo rolls out OriginOS 6 (Android 16) update to Vivo V40

    January 13, 2026

    Alienware Launches New Area-51 Gaming Laptops With RTX 5090, 240Hz OLED Displays, and Cryo-Chamber Cooling

    January 13, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Steam and Valve’s online games are down

    December 24, 2025129 Views

    773,000-year-old fossils found in Casablanca may be earliest common ancestor of modern humans and Neanderthals

    January 8, 202696 Views

    Get three months of Apple Music for only $1 right now

    December 5, 202542 Views
    Don't Miss

    Reid Hoffman Wants Silicon Valley to ‘Stand Up’ Against the Trump Administration

    January 13, 2026

    Reid Hoffman doesn’t do much in half measures. He cofounded LinkedIn, of course, and helped…

    Smartphone Camera Scores Explained: Are DxOMark Rankings Really Reliable?

    January 13, 2026

    Samsung Pushes Galaxy Watch 8 (2025) to Its Lowest Price in New Year Clearance, While Apple Watches Stay Full Price

    January 13, 2026

    Hubble Nets Menagerie of Young Stellar Objects

    January 13, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    8.9

    Review: Dell’s New Tablet PC Can Survive -20f And Drops

    January 15, 2021

    Review: Kia EV6 2022 The Best Electric Vehicle Ever?

    January 14, 2021
    72

    Review: Animation Software Business Share, Market Size and Growth

    January 14, 2021
    Most Popular

    Steam and Valve’s online games are down

    December 24, 2025129 Views

    773,000-year-old fossils found in Casablanca may be earliest common ancestor of modern humans and Neanderthals

    January 8, 202696 Views

    Get three months of Apple Music for only $1 right now

    December 5, 202542 Views
    Our Picks

    Reid Hoffman Wants Silicon Valley to ‘Stand Up’ Against the Trump Administration

    January 13, 2026

    Smartphone Camera Scores Explained: Are DxOMark Rankings Really Reliable?

    January 13, 2026

    Samsung Pushes Galaxy Watch 8 (2025) to Its Lowest Price in New Year Clearance, While Apple Watches Stay Full Price

    January 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Toolcome
    Facebook X (Twitter) Instagram YouTube Mastodon Bluesky
    • Home
    • Technology
    • Gaming
    • Mobile Phones
    • Cars
    • PC Accessories
    © 2026 Tolcome.

    Type above and press Enter to search. Press Esc to cancel.