By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Samsung Zero-Click Flaw Exploited to Deploy LANDFALL Android Spyware via WhatsApp
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Samsung Zero-Click Flaw Exploited to Deploy LANDFALL Android Spyware via WhatsApp
Computing

Samsung Zero-Click Flaw Exploited to Deploy LANDFALL Android Spyware via WhatsApp

News Room
Last updated: 2025/11/07 at 1:38 PM
News Room Published 7 November 2025
Share
Samsung Zero-Click Flaw Exploited to Deploy LANDFALL Android Spyware via WhatsApp
SHARE

Nov 07, 2025Ravie LakshmananMobile Security / Vulnerability

A now-patched security flaw in Samsung Galaxy Android devices was exploited as a zero-day to deliver a “commercial-grade” Android spyware dubbed LANDFALL in targeted attacks in the Middle East.

The activity involved the exploitation of CVE-2025-21042 (CVSS score: 8.8), an out-of-bounds write flaw in the “libimagecodec.quram.so” component that could allow remote attackers to execute arbitrary code, according to Palo Alto Networks Unit 42. The issue was addressed by Samsung in April 2025.

“This vulnerability was actively exploited in the wild before Samsung patched it in April 2025, following reports of in-the-wild attacks,” Unit 42 said. Potential targets of the activity, tracked as CL-UNK-1054, are located in Iraq, Iran, Turkey, and Morocco based on VirusTotal submission data.

The development comes as Samsung disclosed in September 2025 that another flaw in the same library (CVE-2025-21043, CVSS score: 8.8) had also been exploited in the wild as a zero-day. There is no evidence of this security flaw being weaponized in the LANDFALL campaign.

DFIR Retainer Services

It’s assessed that the attacks involved sending via WhatsApp malicious images in the form of DNG (Digital Negative) files, with evidence of LANDFALL samples going all the way back to July 23, 2024. This is based on DNG artifacts bearing names like “WhatsApp Image 2025-02-10 at 4.54.17 PM.jpeg” and “IMG-20240723-WA0000.jpg.”

LANDFALL, once installed and executed, acts as a comprehensive spy tool, capable of harvesting sensitive data, including microphone recording, location, photos, contacts, SMS, files, and call logs. The exploit chain is said to have likely involved the use of a zero-click approach to trigger exploitation of CVE-2025-21042 without requiring any user interaction.

Flowchart for LANDFALL spyware

It’s worth noting that around the same time WhatsApp disclosed that a flaw in its messaging app for iOS and macOS (CVE-2025-55177, CVSS score: 5.4) was chained along with CVE-2025-43300 (CVSS score: 8.8), a flaw in Apple iOS, iPadOS, and macOS, to potentially target less than 200 users as part of a sophisticated campaign. Apple and WhatsApp have since patched the flaws.

Timeline for recent malicious DNG image files and associated exploit activity

Unit 42’s analysis of the discovered DNG files show that they come with an embedded ZIP file appended to the end of the file, with the exploit being used to extract a shared object library from the archive to run the spyware. Also present in the archive is another shared object that’s designed to manipulate the device’s SELinux policy to grant LANDFALL elevated permissions and facilitate persistence.

CIS Build Kits

The shared object that loads LANDFALL also communicates with a command-and-control (C2) server over HTTPS to enter into a beaconing loop and receive unspecified next-stage payloads for subsequent execution.

It’s currently not known who is behind the spyware or the campaign. That said, Unit 42 said LANDFALL’s C2 infrastructure and domain registration patterns dovetail with that of Stealth Falcon (aka FruityArmor), although, as of October 2025, no direct overlaps between the two clusters have been detected.

“From the initial appearance of samples in July 2024, this activity highlights how sophisticated exploits can remain in public repositories for an extended period before being fully understood,” Unit 42 said.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Report: Thanksgiving Turkeys Are 75% More Expensive Than This Time Last Year Report: Thanksgiving Turkeys Are 75% More Expensive Than This Time Last Year
Next Article Anker’s 521 PowerHouse can power up to six devices, and it’s on sale Anker’s 521 PowerHouse can power up to six devices, and it’s on sale
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Don’t Sleep on This Brooklinen Flash Sale
Don’t Sleep on This Brooklinen Flash Sale
Gadget
NILFS2 File-System Seeing Renewed Interest With Additional Maintainer
NILFS2 File-System Seeing Renewed Interest With Additional Maintainer
Computing
You Can Buy Confiscated Items From The TSA – Here’s How – BGR
You Can Buy Confiscated Items From The TSA – Here’s How – BGR
News
Sat, 11/08/2025 – 18:00 – Editors Summary
News

You Might also Like

NILFS2 File-System Seeing Renewed Interest With Additional Maintainer
Computing

NILFS2 File-System Seeing Renewed Interest With Additional Maintainer

2 Min Read
When AI Meets Fashion: Join the Fashion Tech Forum at BEYOND Expo 2025 for a Deep Dive into Creativity [Speakers and Topics Announced] · TechNode
Computing

When AI Meets Fashion: Join the Fashion Tech Forum at BEYOND Expo 2025 for a Deep Dive into Creativity [Speakers and Topics Announced] · TechNode

2 Min Read
How to Choose a Dependency: Build vs Buy, Risk Management, and More | HackerNoon
Computing

How to Choose a Dependency: Build vs Buy, Risk Management, and More | HackerNoon

14 Min Read
China’s Geely, Dongfeng to be first automakers to embrace DeepSeek · TechNode
Computing

China’s Geely, Dongfeng to be first automakers to embrace DeepSeek · TechNode

2 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?