16:42 10 November, 2025Researchers from Palo Alto Networks’ Unit 42 have discovered a new espionage campaign using a previously unknown Android malware called Landfall. The virus exploited a zero-day vulnerability in Samsung Galaxy smartphones, allowing devices to be infected simply by receiving an image — without any user interaction. The finding was reported by TechCrunch. Samsung has already released a patch, though the details of the incident remain undisclosed.
How Landfall Works: Infection Through a Single Image
The vulnerability, CVE-2025-21042, affects Samsung’s proprietary graphics library and allows arbitrary code execution when processing a specially crafted image file. Infection occurs automatically: it is enough to receive a photo via a messenger app such as WhatsApp, Telegram, or even SMS.
No clicks, downloads, or permissions are required.
Once active, Landfall gains access to:
The malware disguises itself as a system process and uses encrypted communication with its command-and-control (C&C) servers.
Who’s Behind It: Traces Lead to the Middle East
Data from VirusTotal shows that most detected samples came from Morocco, Iran, Iraq, and Turkey, suggesting a regional focus. Unit 42 also found overlaps between Landfall’s infrastructure and that of Stealth Falcon, a surveillance project from the UAE (2012) used to spy on journalists and activists. However, no confirmed link to a specific state or private group has been established yet.
Affected models include Galaxy S22, S23, S24, and foldable Galaxy Z Flip/Fold devices. The attack began in July 2024 and remains active as of late 2025.
Samsung’s Response: Patch and User Guidance
Samsung addressed the vulnerability in its October 2025 Security Maintenance Release (SMR Oct-2025). The patch rollout schedule is as follows:
Recommended actions:
In Brief
A new spy malware called Landfall can steal data from Samsung Galaxy phones via a single image — no clicks needed. Models affected include the S22, S23, S24, and foldables. The vulnerability CVE-2025-21042 has been patched in Samsung’s October 2025 update. Users should update their devices immediately.
The campaign appears to be targeted, with a focus on the Middle East. Samsung has not revealed full details, but the security issue is now resolved.