Researchers from Palo Alto Networks’ Unit 42 have discovered a new espionage campaign using a previously unknown Android malware called Landfall. The virus exploited a zero-day vulnerability in Samsung Galaxy smartphones, allowing devices to be infected simply by receiving an image — without any user interaction. The finding was reported by TechCrunch. Samsung has already released a patch, though the details of the incident remain undisclosed.
How Landfall Works: Infection Through a Single Image
The vulnerability, CVE-2025-21042, affects Samsung’s proprietary graphics library and allows arbitrary code execution when processing a specially crafted image file. Infection occurs automatically: it is enough to receive a photo via a messenger app such as WhatsApp, Telegram, or even SMS.
No clicks, downloads, or permissions are required.
Once active, Landfall gains access to:
- Photos and videos
- Messages (SMS and chat apps)
- Contacts and call history
- Real-time location
- Microphone (for remote audio recording)
The malware disguises itself as a system process and uses encrypted communication with its command-and-control (C&C) servers.
Who’s Behind It: Traces Lead to the Middle East
Data from VirusTotal shows that most detected samples came from Morocco, Iran, Iraq, and Turkey, suggesting a regional focus. Unit 42 also found overlaps between Landfall’s infrastructure and that of Stealth Falcon, a surveillance project from the UAE (2012) used to spy on journalists and activists. However, no confirmed link to a specific state or private group has been established yet.
Affected models include Galaxy S22, S23, S24, and foldable Galaxy Z Flip/Fold devices. The attack began in July 2024 and remains active as of late 2025.
Samsung’s Response: Patch and User Guidance
Samsung addressed the vulnerability in its October 2025 Security Maintenance Release (SMR Oct-2025). The patch rollout schedule is as follows:
- Galaxy S24/S23 — update available globally
- Galaxy S22, Z Fold/Flip — rollout during November
- Older models (S21 and below) — partial rollout depending on region
Recommended actions:
- Go to Settings → Software Update → Download and Install.
- Ensure your security patch level is October 2025 or newer.
- Avoid opening or previewing suspicious images from unknown senders.
- Use Google Play Protect and reputable antivirus tools like Kaspersky or Bitdefender.
In Brief
A new spy malware called Landfall can steal data from Samsung Galaxy phones via a single image — no clicks needed. Models affected include the S22, S23, S24, and foldables. The vulnerability CVE-2025-21042 has been patched in Samsung’s October 2025 update. Users should update their devices immediately.
The campaign appears to be targeted, with a focus on the Middle East. Samsung has not revealed full details, but the security issue is now resolved.






