Landfall virus steals data without a click: Samsung Galaxy users at risk

November 10, 2025  16:42

Researchers from Palo Alto Networks’ Unit 42 have discovered a new espionage campaign using a previously unknown Android malware called Landfall. The virus exploited a zero-day vulnerability in Samsung Galaxy smartphones, allowing devices to be infected simply by receiving an image — without any user interaction. The finding was reported by TechCrunch. Samsung has already released a patch, though the details of the incident remain undisclosed.

How Landfall Works: Infection Through a Single Image

The vulnerability, CVE-2025-21042, affects Samsung’s proprietary graphics library and allows arbitrary code execution when processing a specially crafted image file. Infection occurs automatically: it is enough to receive a photo via a messenger app such as WhatsApp, Telegram, or even SMS.
No clicks, downloads, or permissions are required.

Once active, Landfall gains access to:

  • Photos and videos
  • Messages (SMS and chat apps)
  • Contacts and call history
  • Real-time location
  • Microphone (for remote audio recording)

The malware disguises itself as a system process and uses encrypted communication with its command-and-control (C&C) servers.

Who’s Behind It: Traces Lead to the Middle East

Data from VirusTotal shows that most detected samples came from Morocco, Iran, Iraq, and Turkey, suggesting a regional focus. Unit 42 also found overlaps between Landfall’s infrastructure and that of Stealth Falcon, a surveillance project from the UAE (2012) used to spy on journalists and activists. However, no confirmed link to a specific state or private group has been established yet.

Affected models include Galaxy S22, S23, S24, and foldable Galaxy Z Flip/Fold devices. The attack began in July 2024 and remains active as of late 2025.

Samsung’s Response: Patch and User Guidance

Samsung addressed the vulnerability in its October 2025 Security Maintenance Release (SMR Oct-2025). The patch rollout schedule is as follows:

  • Galaxy S24/S23 — update available globally
  • Galaxy S22, Z Fold/Flip — rollout during November
  • Older models (S21 and below) — partial rollout depending on region

Recommended actions:

  1. Go to Settings → Software Update → Download and Install.
  2. Ensure your security patch level is October 2025 or newer.
  3. Avoid opening or previewing suspicious images from unknown senders.
  4. Use Google Play Protect and reputable antivirus tools like Kaspersky or Bitdefender.

In Brief

A new spy malware called Landfall can steal data from Samsung Galaxy phones via a single image — no clicks needed. Models affected include the S22, S23, S24, and foldables. The vulnerability CVE-2025-21042 has been patched in Samsung’s October 2025 update. Users should update their devices immediately.
The campaign appears to be targeted, with a focus on the Middle East. Samsung has not revealed full details, but the security issue is now resolved.


 
 
 
 
  • Archive