Newly identified Android spyware appears to be from a commercial vendor
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-21042 | Out-of-Bounds Write RCE in Samsung Mobile Image Codec (libimagecodec.quram.so) CVE-2025-21042 is an out-of-bounds write (CWE-787) in libimagecodec.quram.so, the Quram image codec library in the image-processing stack of Samsung mobile devices. A remote attacker can trigger the flaw by getting a vulnerable device to decode a crafted image or media file, corrupting memory and potentially executing arbitrary code (the advisory does not specify the exact delivery vector, such as messaging or web content). Successful exploitation allows the attacker to run code on the device, though whether execution is confined to the decoding application or achieves broader privileges is not stated. Any Samsung mobile device using the affected codec is potentially at risk; CISA lists the product only as 'Samsung Mobile Devices' without model or version detail. The flaw is confirmed to be exploited in the wild: CISA added it to the KEV catalog on 2025-11-10 (ransomware use unknown), no public PoC is known, and EPSS assigns a 33.2% probability of exploitation within 30 days (98th percentile). Do: Install the latest Samsung security maintenance release (SMR) / monthly security update on all Samsung mobile devices and verify each device's Android security patch level includes the fix for this CVE; per CISA's KEV required action, apply the vendor's mitigations, and federal civilian agencies must follow BOD 22-01 or discontinue use of affected products. Until the update is confirmed, treat untrusted image/media files (e.g., received via messaging or web) as a risk vector on Samsung devices and monitor Samsung's security advisories for the affected-model list. | 9.8 | 33% | KEV |
| masshundreds of millions to roughly a billion Samsung mobile devices in use worldwide (order of magnitude 10^8-10^9) |
Full article516 words · extracted from therecord.media · click to collapse
Security researchers on Friday revealed the discovery of “commercial grade” spyware used in a 9-month-long hacking campaign aimed at Samsung Galaxy phones likely concentrated in the Middle East. The Android spyware, dubbed LANDFALL, exploited a zero-day, or previously undocumented, vulnerability in Galaxy phones’ image processing libraries. The spyware was likely sent via the WhatsApp messaging platform to exfiltrate data and snoop on targets. LANDFALL, which may have been zero-click, allowed microphone recording, location tracking, call recording, collection of photos and text message, contacts and call history exfiltration, according to researchers at Palo Alto Networks’ Unit 42. Zero-click spyware requires no direct action from a device user. The security flaw was patched in April 2025 and has been tracked as CVE-2025-21042. The hackers sent victims malformed Digital Negative (DNG) images — a form of TIFF image files. The images had an “embedded ZIP archive appended to the end of the file” that exploited the bug. Unit 42 said. The campaign shares “tradecraft patterns” and infrastructure with commercial spyware operations in the Middle East, suggesting potential ties to private sector manufacturers, the researchers said in a blog post. The vendor and government behind LANDFALL remain unknown and it is not clear how many people were targeted, according to Unit 42. Researchers there believe the campaign was designed for snooping. "This was not mass-distributed malware but a precision attack,” said Itay Cohen, a senior principal researcher at Unit 42. “The sophisticated infrastructure, bespoke payload design, and use of zero-day vulnerabilities are all hallmarks of an espionage-motivated operation, not a financial or consumer-scale campaign." LANDFALL’s command and control infrastructure and domain registration patterns are similar to those used by Stealth Falcon, a hacking group with strong ties to the United Arab Emirates, the researchers said. Stealth Falcon has been tied to dozens of spyware cases involving countries in Africa and the Middle East. There are no “direct overlaps” between LANDFALL’s mobile campaigns and the “endpoint-based activity from Stealth Falcon, nor direct strong links with Stealth Falcon,” the blog post said. “However, the similarities are worth discussion.” The LANDFALL samples the researchers found were submitted to the VirusTotal repository in 2024 and 2025, the researchers said, indicating potential targets in Iraq, Iran, Turkey and Morocco. Turkey's cyber readiness team, known as USOM, also reported IP addresses used by LANDFALL's command and control servers as malicious, suggesting possible Turkish victims, the researchers said. The vulnerability was privately reported to Samsung in September 2024 but the company did not release a firmware update to fix it until April 2025, the researchers said. Samsung did not respond to a request for comment. Targeted device models include the Galaxy ZFOLD4, Galaxy ZFlip4 and S22, 23 and S24 Series, according to the blog post.
No previous article
No new articles
Suzanne Smalley
is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/landfall-spyware-middle-east-appears-commercial-grade