{"id":278683,"date":"2025-11-08T05:35:14","date_gmt":"2025-11-08T05:35:14","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/278683\/"},"modified":"2025-11-08T05:35:14","modified_gmt":"2025-11-08T05:35:14","slug":"samsung-mobile-flaw-exploited-as-zero-day-to-deploy-landfall-android-spyware","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/278683\/","title":{"rendered":"Samsung Mobile Flaw Exploited as Zero-Day to Deploy LANDFALL Android Spyware"},"content":{"rendered":"<p>\ue802Nov 07, 2025\ue804Ravie LakshmananMobile Security \/ Vulnerability<\/p>\n<p><a href=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/11\/mobile-exploit.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/11\/mobile-exploit.jpg\" alt=\"Zero-Day to Deploy LANDFALL Android Spyware\" border=\"0\" data-original-height=\"470\" data-original-width=\"900\" title=\"Zero-Day to Deploy LANDFALL Android Spyware\"\/><\/a><\/p>\n<p>A now-patched security flaw in Samsung Galaxy Android devices was exploited as a zero-day to deliver a &#8220;commercial-grade&#8221; Android spyware dubbed LANDFALL in targeted attacks in the Middle East.<\/p>\n<p>The activity involved the exploitation of <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-21042\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2025-21042<\/a> (CVSS score: 8.8), an out-of-bounds write flaw in the &#8220;libimagecodec.quram.so&#8221; component that could allow remote attackers to execute arbitrary code, according to Palo Alto Networks Unit 42. The issue was <a href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb?year=2025&amp;month=04\" rel=\"nofollow noopener\" target=\"_blank\">addressed<\/a> by Samsung in April 2025.<\/p>\n<p>&#8220;This vulnerability was actively exploited in the wild before Samsung patched it in April 2025, following reports of in-the-wild attacks,&#8221; Unit 42 <a href=\"https:\/\/unit42.paloaltonetworks.com\/landfall-is-new-commercial-grade-android-spyware\/\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a>. Potential targets of the activity, tracked as CL-UNK-1054, are located in Iraq, Iran, Turkey, and Morocco based on VirusTotal submission data.<\/p>\n<p>The development comes as Samsung <a href=\"https:\/\/thehackernews.com\/2025\/09\/samsung-fixes-critical-zero-day-cve.html\" rel=\"nofollow noopener\" target=\"_blank\">disclosed<\/a> in September 2025 that another flaw in the same library (CVE-2025-21043, CVSS score: 8.8) had also been exploited in the wild as a zero-day. There is no evidence of this security flaw being weaponized in the LANDFALL campaign. Samsung did not immediately respond to a request for comment.<\/p>\n<p><a href=\"https:\/\/thehackernews.uk\/zz--inside-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"DFIR Retainer Services\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/11\/zz--inside-d.png\" width=\"729\" height=\"91\"\/><\/a><\/p>\n<p>It&#8217;s assessed that the attacks involved sending via WhatsApp malicious images in the form of <a href=\"https:\/\/en.wikipedia.org\/wiki\/Digital_Negative\" rel=\"nofollow noopener\" target=\"_blank\">DNG<\/a> (Digital Negative) files, with evidence of LANDFALL samples going all the way back to July 23, 2024. This is based on DNG artifacts bearing names like &#8220;WhatsApp Image 2025-02-10 at 4.54.17 PM.jpeg&#8221; and &#8220;IMG-20240723-WA0000.jpg.&#8221;<\/p>\n<p>LANDFALL, once installed and executed, acts as a comprehensive spy tool, capable of harvesting sensitive data, including microphone recording, location, photos, contacts, SMS, files, and call logs.<\/p>\n<p>While Unit 42 said the exploit chain may have involved the use of a zero-click approach to trigger the exploitation of CVE-2025-21042 without requiring any user interaction, there are currently no indications that it has happened or there exists an unknown security issue in WhatsApp to support this hypothesis.<\/p>\n<p>The Android spyware is specifically designed to target Samsung&#8217;s Galaxy S22, S23, and S24 series devices, as well as Z Fold 4 and Z Flip 4, covering some of the flagship devices from the South Korean electronics chaebol, with the exception of the latest generation.<\/p>\n<p><a href=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/11\/1000031603.png\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/11\/1000031603.png\" alt=\"\" border=\"0\" data-original-height=\"1298\" data-original-width=\"2048\"\/><\/a>Flowchart for LANDFALL spyware<\/p>\n<p>It&#8217;s worth noting that around the same time WhatsApp disclosed that a flaw in its messaging app for iOS and macOS (<a href=\"https:\/\/thehackernews.com\/2025\/08\/whatsapp-issues-emergency-update-for.html\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2025-55177<\/a>, CVSS score: 5.4) was chained along with <a href=\"https:\/\/thehackernews.com\/2025\/08\/apple-patches-cve-2025-43300-zero-day.html\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2025-43300<\/a> (CVSS score: 8.8), a flaw in Apple iOS, iPadOS, and macOS, to potentially target less than 200 users as part of a sophisticated campaign. Apple and WhatsApp have since patched the flaws.<\/p>\n<p><a href=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/11\/1000031615.png\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/11\/1000031615.png\" alt=\"\" border=\"0\" data-original-height=\"1675\" data-original-width=\"2048\"\/><\/a>Timeline for recent malicious DNG image files and associated exploit activity<\/p>\n<p>Unit 42&#8217;s analysis of the discovered DNG files show that they come with an embedded ZIP file appended to the end of the file, with the exploit being used to extract a shared object library from the archive to run the spyware. Also present in the archive is another shared object that&#8217;s designed to manipulate the device&#8217;s <a href=\"https:\/\/www.redhat.com\/en\/topics\/linux\/what-is-selinux\" rel=\"nofollow noopener\" target=\"_blank\">SELinux<\/a> policy to grant LANDFALL elevated permissions and facilitate persistence.<\/p>\n<p><a href=\"https:\/\/thehackernews.uk\/endpoint-protect-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"CIS Build Kits\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/11\/sem-d.png\" width=\"729\" height=\"91\"\/><\/a><\/p>\n<p>The shared object that loads LANDFALL also communicates with a command-and-control (C2) server over HTTPS to enter into a beaconing loop and receive unspecified next-stage payloads for subsequent execution.<\/p>\n<p>It&#8217;s currently not known who is behind the spyware or the campaign. That said, Unit 42 said LANDFALL&#8217;s C2 infrastructure and domain registration patterns dovetail with that of <a href=\"https:\/\/thehackernews.com\/2025\/06\/microsoft-patches-67-vulnerabilities.html\" rel=\"nofollow noopener\" target=\"_blank\">Stealth Falcon<\/a> (aka FruityArmor), although, as of October 2025, no direct overlaps between the two clusters have been detected.<\/p>\n<p>&#8220;From the initial appearance of samples in July 2024, this activity highlights how sophisticated exploits can remain in public repositories for an extended period before being fully understood,&#8221; Unit 42 said.<\/p>\n","protected":false},"excerpt":{"rendered":"\ue802Nov 07, 2025\ue804Ravie LakshmananMobile Security \/ Vulnerability A now-patched security flaw in Samsung Galaxy Android devices was exploited&hellip;\n","protected":false},"author":2,"featured_media":278684,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[5407,5400,5393,5392,5394,5395,5396,5401,5397,5398,5403,5405,5404,5402,5399,74,5406],"class_list":["post-278683","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-computer-security","tag-cyber-attacks","tag-cyber-news","tag-cyber-security-news","tag-cyber-security-news-today","tag-cyber-security-updates","tag-cyber-updates","tag-data-breach","tag-hacker-news","tag-hacking-news","tag-how-to-hack","tag-information-security","tag-network-security","tag-ransomware-malware","tag-software-vulnerability","tag-technology","tag-the-hacker-news"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/278683","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=278683"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/278683\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/278684"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=278683"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=278683"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=278683"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}