Close Menu
Must Have Gadgets –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    SpaceX Is Bricking Select Starlink Dishes on Nov. 17. Here’s How to Protect Yours

    November 10, 2025

    We found the best sales from Apple, Amazon, Lego, Dyson and more

    November 10, 2025

    9 Best Shower Filters (2025), WIRED Tested and Approved

    November 10, 2025
    Facebook X (Twitter) Instagram
    Must Have Gadgets –
    Trending
    • SpaceX Is Bricking Select Starlink Dishes on Nov. 17. Here’s How to Protect Yours
    • We found the best sales from Apple, Amazon, Lego, Dyson and more
    • 9 Best Shower Filters (2025), WIRED Tested and Approved
    • My favorite AirTag alternative just got a worthy successor – and it’s a design marvel
    • Marshall Heston 60 review: a hard-hitting yet conveniently compact Dolby Atmos soundbar
    • 5 supernatural shows scarier, weirder, and darker than Stranger Things
    • Nintendo Switch 2 Carrying Case & Screen Protector review: Nintendo’s official model is durable, stylish, and slim
    • Apple iPad Mini is 20% Off Right Now » nextpit
    • Home
    • Shop
      • Earbuds & Headphones
      • Smartwatches
      • Mobile Accessories
      • Smart Home Devices
      • Laptops & Tablets
    • Gadget Reviews
    • How-To Guides
    • Mobile Accessories
    • Smart Devices
    • More
      • Top Deals
      • Smart Home
      • Tech News
      • Trending Tech
    Facebook X (Twitter) Instagram
    Must Have Gadgets –
    Home»Mobile Accessories»These Galaxy phones were attacked by spyware for nearly a year before a patch was released
    Mobile Accessories

    These Galaxy phones were attacked by spyware for nearly a year before a patch was released

    adminBy adminNovember 10, 2025No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    These Galaxy phones were attacked by spyware for nearly a year before a patch was released
    Share
    Facebook Twitter LinkedIn Pinterest Email


    A zero-day vulnerability (CVE-2025-21042) in Samsung’s Android image processing library allowed attackers to embed spyware called LANDFALL in Samsung devices including Galaxy handsets. Here are some definitions; a zero-day vulnerability is one that no one knows about giving the developer zero days to come up with a way to patch the flaw. Samsung’s Android image processing library handles the decoding and processing of various image formats, including some formats that are proprietary to Samsung.

    The LANDFALL spyware impacted certain Samsung phones

    The thing is, LANDFALL was exploited in the wild before Samsung was able to patch the vulnerability this past April. However, the exploitation and the spyware employed have never been discussed publicly until this past week. LANDFALL was embedded in malicious DNG image files that were sent via WhatsApp. According to the Palo Alto Network, LANDFALL was operating in the middle of 2024 which was months before the vulnerability was patched.As for the involvement of WhatsApp delivering the Samsung exploit, this has been denied by WhatsApp owner Meta according to a report from Forbes. Meta says that it has not found any basis to support this aspect of the story and says that there is no evidence to support the claim.

    LANDFALL hasn’t been a threat since this past April although another zero-day vulnerability was patched by Samsung just two months ago during September. This flaw (CVE-2025-21043) was also found in the imaging processing library. The patch prevents any attack from taking place.

    The spyware used microphone recording, location tracking, and photos for surveillance 

    Itay Cohen, a senior principal researcher at Palo Alto Network’s Unit 42 said that the LANDFALL attack was targeted at certain individuals and was not mass-distributed. Cohen says that the motive for these attacks was espionage.

    Flowchart for the LANDFALL spyware. | Image credit-Techworm

    We should point out that the LANDFALL spyware was designed for attacks against the Samsung Galaxy line mostly with targeted attacks taking place primarily in the Middle East including Turkey, Iran, Iraq, and Morocco. Being spyware, it shouldn’t be a surprise that LANDFALL used microphone recording, location tracking, photos, contacts. A malformed image file, one that has been deliberately corrupted to set off a flaw in the software that reads the file, was used in the attacks. No clicks were required to exploit the vulnerability.

    As soon as the image was received by the targeted Galaxy phone, the device was compromised. Once these photos were opened or previewed, the phone could be used by attackers to:

    • Record microphone audio and phone calls.
    • In real time, track GPS location.
    • Access photos, messages, contacts, call logs, and browsing history.
    • Hide from antivirus scans and even remain active after reboots.

    Reports say that the Samsung phones most attacked by LANDFALL include the Galaxy S22 line. Galaxy S23 line, Galaxy S24 line, Z Fold 4 and Z Flip 4 foldables. The Galaxy S25 series was not targeted by the spyware. 

    For 10 months targeted phones were extremely vulnerable

    There was a period of 10 months between the time the campaign began in July 2024 and when the flaw was patched in April of this year when the aforementioned Galaxy models were at the peak of their vulnerability. When Samsung patched the vulnerability this past April, the company made no public statement about it.

    Security experts recommend that Samsung Galaxy users with a handset powered by Android 13-15 make sure that they installed the April 2025 Android Security update or later just to make sure that they have the exploit patched on their phones. Automatic media downloads for messaging apps like WhatsApp and Telegram should be disabled. They should also enable Android’s Advanced Protection mode or iOS’s Lockdown Mode if they consider themselves to be a high-risk user.

    Iconic Phones is now up for pre-order in the US!

    Our new coffee table book, Iconic Phones, is a stunning visual tribute to the legends in the world of phones, featuring exclusive high-resolution photography, stories, quotes and fun trivia. Pre-order now and save 15% with code: PARENA15


    Pre-order now

    Read the latest from Alan Friedman

    attacked Galaxy patch phones Released Spyware year
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    admin
    • Website

    Related Posts

    Apple iPad Mini is 20% Off Right Now » nextpit

    November 10, 2025

    Samsung should not release the Galaxy Z Fold 8 if it’s missing these 2 features

    November 10, 2025

    Gigabyte Gaming A16 Pro review: this restricted RTX 5080 machine holds its own thanks to 5070 Ti pricing

    November 10, 2025
    Leave A Reply Cancel Reply

    Top Posts

    SpaceX Is Bricking Select Starlink Dishes on Nov. 17. Here’s How to Protect Yours

    November 10, 2025

    PayPal’s blockchain partner accidentally minted $300 trillion in stablecoins

    October 16, 2025

    The best AirPods deals for October 2025

    October 16, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    How-To Guides

    How to Disable Some or All AI Features on your Samsung Galaxy Phone

    By adminOctober 16, 20250
    Gadget Reviews

    PayPal’s blockchain partner accidentally minted $300 trillion in stablecoins

    By adminOctober 16, 20250
    Smart Devices

    The best AirPods deals for October 2025

    By adminOctober 16, 20250

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Latest Post

    SpaceX Is Bricking Select Starlink Dishes on Nov. 17. Here’s How to Protect Yours

    November 10, 2025

    We found the best sales from Apple, Amazon, Lego, Dyson and more

    November 10, 2025

    9 Best Shower Filters (2025), WIRED Tested and Approved

    November 10, 2025
    Recent Posts
    • SpaceX Is Bricking Select Starlink Dishes on Nov. 17. Here’s How to Protect Yours
    • We found the best sales from Apple, Amazon, Lego, Dyson and more
    • 9 Best Shower Filters (2025), WIRED Tested and Approved
    • My favorite AirTag alternative just got a worthy successor – and it’s a design marvel
    • Marshall Heston 60 review: a hard-hitting yet conveniently compact Dolby Atmos soundbar

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 must-have-gadgets.

    Type above and press Enter to search. Press Esc to cancel.