Security researchers uncovered a sophisticated Android spyware campaign, dubbed LANDFALL, which specifically targeted Samsung Galaxy devices using a previously unknown zero-day vulnerability (CVE-2025-21042) in the image processing library. Attackers delivered the spyware through malicious DNG image files, likely sent via WhatsApp, enabling comprehensive surveillance capabilities such as microphone recording, location tracking, call and message exfiltration, and more. The campaign, believed to have operated primarily in the Middle East, was characterized by its precision targeting and use of advanced tradecraft, including zero-click exploitation and infrastructure patterns reminiscent of commercial spyware vendors. Samsung patched the vulnerability in April 2025, mitigating ongoing risk for current users.
The LANDFALL operation was not a mass malware campaign but a targeted espionage effort, with researchers noting similarities to other commercial-grade spyware activities in the region. The vendor and government sponsor behind LANDFALL remain unidentified, and the full scope of affected individuals is unclear. The campaign's infrastructure and domain registration patterns suggest possible links to known threat actors, but attribution remains unconfirmed. Researchers emphasize that the operation predates other high-profile exploit chains involving similar vulnerabilities, highlighting the evolving threat landscape for mobile device users, especially those in sensitive regions or roles.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On November 10, 2025, CISA added Samsung flaw CVE-2025-21042 to its Known Exploited Vulnerabilities catalog after public reporting on its use in LANDFALL spyware attacks. CISA ordered U.S. federal civilian agencies to remediate the issue under BOD 22-01 and set a deadline of December 1, 2025.
On November 7, 2025, Palo Alto Networks Unit 42 published research on the previously unknown LANDFALL Android spyware family and its exploit chain targeting Samsung Galaxy devices. The report described modular spyware capabilities, six C2 endpoints, likely victim geography including Iraq, Iran, Turkey, and Morocco, and possible WhatsApp-based zero-click delivery via malformed DNG files.
By October 2025, Unit 42 had assessed that LANDFALL infrastructure and registration patterns resembled activity associated with Stealth Falcon and other Middle East commercial spyware ecosystems, but it had not found direct overlap sufficient for attribution. The operation remained unattributed despite these similarities.
Samsung later fixed a second DNG parsing vulnerability in the same image-processing library, tracked as CVE-2025-21043 / SVE-2025-1702, in September 2025. Unit 42 said it found no evidence that LANDFALL used this second flaw.
Apple patched CVE-2025-43300, a similar DNG image-processing vulnerability in iOS, in August 2025. Multiple reports said this helped prompt further scrutiny of Samsung's image parsing issues and highlighted a broader pattern of DNG-based mobile exploitation.
Samsung patched the exploited out-of-bounds write vulnerability CVE-2025-21042 in libimagecodec.quram.so in April 2025. The flaw had been used to deliver LANDFALL spyware through crafted DNG images, likely via WhatsApp and potentially in a zero-click chain.
According to later reporting, Samsung received a report from Meta and the WhatsApp Security Teams about the libimagecodec.quram.so flaw CVE-2025-21042 after it had been exploited in the wild. This private disclosure preceded Samsung's fix.
Palo Alto Networks Unit 42 said it observed artifacts tied to the LANDFALL Android spyware operation in public repositories as early as July 2024, indicating the campaign was active by then. The activity targeted Samsung Galaxy devices, primarily in the Middle East, using malicious DNG image files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcesocradar.io
Open sourcescworld.com
Open sourcethecyberthrone.in
Open sourcedarkreading.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.