logo

LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices

ID: b696f0b1-8fd8-508d-baf8-e47eb9704e28

STIX ID: report--b696f0b1-8fd8-508d-baf8-e47eb9704e28

Feed Name: Palo Alto Networks Unit 42

Threat Score
85/100

Date Published: 2025-11-07

Date Updated: 2026-04-28

Author: Unit 42

...
...

Unit 42 discovered LANDFALL, a previously undescribed commercial-grade Android spyware used in targeted surveillance of Samsung Galaxy devices; attackers delivered the spyware via malformed DNG image files exploiting a zero-day in Samsung’s image processing library (CVE-2025-21042) in the wild from mid‑2024 until the April 2025 patch. The analysis describes loader and SELinux-manipulation components, extensive data‑collection capabilities (microphone, calls, location, files), C2 infrastructure and IoCs, likely WhatsApp-based delivery, ties to Middle East targeting, and similarities to commercial/private-sector offensive spyware tradecraft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.