LANDFALL is the name used for an Android spyware operation and associated spyware family targeting Samsung Galaxy devices. It has been described as commercial-grade spyware and assessed as part of a cyber-mercenary or private-sector offensive actor ecosystem rather than a publicly established traditional APT designation. Reported victimology has included high-value targets in the Middle East, North Africa, and South Asia, with observed targeting in countries including Iraq, Iran, Turkey, Bahrain, Morocco, and Pakistan. The operation is notable for chaining a Samsung image-processing vulnerability, identified as CVE-2025-21042, with a zero-click WhatsApp delivery mechanism. Reported tradecraft indicates that a malicious image sent to a target’s WhatsApp inbox could trigger compromise without user interaction, enabling device intrusion while bypassing the protections of encrypted messaging by attacking the endpoint rather than the protocol. Research has linked the spyware to exploit-chain development involving Samsung DNG/TIFF parsing. LANDFALL should be understood primarily as a spyware family or campaign cluster rather than a mature, widely tracked intrusion set with a broad public alias set. Public reporting associates it with a PSOA-linked cluster, indicating likely ties to the private surveillance industry and mercenary spyware activity. Its operational profile aligns with targeted surveillance of selected individuals rather than broad opportunistic crimeware deployment. Known aliases in public reporting are limited, with LANDFALL being the principal name and landfall_operators appearing as a normalized label. No high-confidence sub-groups are publicly established. Tactics associated with the operation include zero-click exploitation, mobile spyware deployment, exploitation of messaging applications for initial access, and abuse of mobile OS or OEM-specific vulnerabilities to gain code execution and persistent surveillance capability.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PSOA-attributed activity cluster using malicious TIFF files with embedded ELF payloads targeting Android, exploiting Samsung TIFF/DNG parsing vulnerability (CVE-2025-21042).
Operators used LANDFALL spyware to compromise Samsung devices via a combination of a Samsung vulnerability and a zero-click WhatsApp exploit.
LANDFALL is a commercial-grade Android spyware used in exploit chains targeting Samsung devices, leveraging vulnerabilities in DNG file processing. The spyware is capable of exfiltrating data and maintaining command and control over infected devices.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.