Spyware Attack via WhatsApp Images Targets Samsung Galaxy Phones: ‘Landfall’ Exploit Exposes Major Security Flaw

Hackers exploited a zero-day flaw in Samsung’s image library to deploy ‘Landfall’ spyware via WhatsApp photos.

Samsung Galaxy smartphones have faced a serious cybersecurity issue as a result of a zero-day vulnerability being exploited through WhatsApp images by a covert spyware campaign that has been discovered by researchers. The spyware, which has been given the name Landfall, had the ability to quietly access devices and no action from the user was required—just getting an image that was infected was sufficient.

Zero-Click Exploit Through WhatsApp Images

According to cybersecurity firm Palo Alto Networks’ Unit 42, hackers took advantage of a flaw in Samsung’s image-processing system to deploy Landfall spyware across several Galaxy models. The vulnerability—CVE-2025-21042—was hidden deep within Samsung’s proprietary image-handling library.

By weaponizing Digital Negative (DNG) files disguised as normal JPEGs, attackers managed to execute a zero-click attack, gaining full control over the device immediately after the image was delivered. Victims did not need to open or tap on the file.

Affected Devices and Timeline

The spyware primarily targeted Samsung Galaxy S22, S23, S24, Z Fold 4, and Z Flip 4 models, especially in the Middle East, including Turkey, Iran, Iraq, and Morocco. The operation reportedly remained undetected for nearly a year before being discovered in mid-2024.

Although Samsung was informed about the flaw in September 2024, the company released a security patch only in April 2025, leaving millions of users vulnerable for months.

Landfall’s Capabilities and Impact

Once installed, Landfall acted as a powerful surveillance tool capable of:

  • Recording phone calls
  • Accessing photos, contacts, and messages
  • Activating the microphone for eavesdropping
  • Tracking users’ real-time location

Investigators said the spyware’s design and techniques resembled those of Stealth Falcon, a group previously linked to state-backed surveillance operations in the UAE, though no direct attribution has yet been confirmed.

“It was a precision attack, not a mass campaign,” said Itay Cohen, Senior Principal Researcher at Unit 42. “That strongly suggests espionage motives rather than financial gain.”

Discovery and Response

The campaign came to light when Unit 42 analysts found several compromised DNG files uploaded to Google’s VirusTotal platform from Middle Eastern IP addresses. Subsequent analysis revealed links to a command-and-control server flagged by Turkey’s national cyber agency, indicating possible targeting of Turkish users.

Samsung has since fixed the vulnerability, but experts warn that the Landfall exploit is a stark reminder of the growing sophistication of mobile cyberattacks. Users are urged to update their devices immediately and remain cautious even with trusted communication apps like WhatsApp.

Cybersecurity experts caution: In today’s threat landscape, even a harmless-looking image could open the door to digital espionage.

vivo X300 Series Launched in India: Flagship Cameras, ZEISS Partnership, and OriginOS 6 Lead the Upgrade

The new vivo X300 and X300 Pro showcasing ZEISS co-engineered imaging and flagship performance.

vivo has officially launched its latest flagship lineup — the vivo X300 and vivo X300 Pro — in India, marking a major leap in smartphone imaging, AI capabilities, and performance. Co-engineered with ZEISS, the new X300

iQOO 15 India Price Leak: Is It Worth Buying? Check Expected Price, Specs & Features

iQOO 15 is expected to launch in India with a 2K LTPO AMOLED display, Snapdragon 8 Gen 5 Elite chipset, and a triple 50MP camera setup, as per leaked details.

iQOO has opened pre-bookings for the upcoming iQOO 15 on Amazon India and the official iQOO India website—ahead of its launch event. A new leak from tipster Abhishek Yadav, originally shared via the TTMrIGL YouTube channel,

20 Trending Google Gemini AI Photo Editing Prompts for Boys: Stylish & Unique Ideas for 2025

Aesthetic AI-generated portrait concepts for boys using Google Gemini, featuring cinematic lighting, street-style fashion, and ultra-realistic visual effects.

Google’s Gemini AI continues to push the boundaries of digital creativity with a fresh set of photo-editing prompts curated specifically for boys. The latest collection — “20 Trending Google Gemini AI Photo Editing Prompts for Boys”

NYT ‘Connections’ Hints and Answers for Today (Thursday, November 20, 2025)

NYT Connections Puzzle #893: Full hints, category clues, and complete answers for November 20, 2025.

If today’s NYT Connections puzzle has you stumped, you’re in good company. The November 20 edition—Puzzle #893—has left many players scratching their heads. Whether you need a small push or the full breakdown, here are today’s

Wordle Answer Today (November 20, 2025): Puzzle #1615 — Hints, Clues & Full Solution

Wordle Answer for November 20, 2025: Puzzle #1615 solved with hints, clues, and the final solution GRAVE.

The Wordle challenge on the 20th of November Thursday turned out to be trickier than usual as Puzzle #1615 was all around something sombre. In case you could not find the clues today, a guide is

Cloudflare Outage Rocks Internet: ChatGPT, X (Twitter) Hit; Downdetector Also Down

A widespread technical fault at Cloudflare caused major platforms, including ChatGPT, X (Twitter), and Downdetector, to experience crippling outages worldwide.

A massive internet outage originating from the web infrastructure giant Cloudflare hit parts of the globe today, rendering access into several major online platforms into non-existence. Services ranging from AI powerhouse Chatbot AI to social network

Advertisement

Recommended For You