logo

New LandFall spyware exploited Samsung zero-day via WhatsApp messages

ID: a67060c9-d1bf-52df-8a46-3593c7728f73

STIX ID: report--a67060c9-d1bf-52df-8a46-3593c7728f73

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-11-07

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

A critical zero‑day vulnerability in Samsung's image processing library (CVE-2025-21042) was exploited to deploy 'LandFall' spyware via malicious DNG images delivered through WhatsApp; Unit 42 observed samples beginning July 2024 targeting Galaxy S22/S23/S24, Z Fold 4, and Z Flip 4 in the Middle East. The DNGs contained an embedded ZIP with a loader (b.so) and a SELinux policy manipulator (l.so) to elevate privileges, persist, and load modules that enable microphone and call recording, location tracking, and access to photos, SMS, contacts, call logs, files, and browsing history; researchers identified C2 servers and infrastructure links but could not confidently attribute the campaign to a specific vendor or group. Recommended mitigations include applying security updates, disabling automatic media download in messaging apps, and enabling advanced mobile protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.