Executive Summary
In mid-2024, security researchers from Palo Alto Networks' Unit 42 uncovered 'Landfall', a sophisticated commercial-grade spyware campaign targeting Samsung Galaxy S22, S23, S24, and Fold/Flip devices in the Middle East, specifically in Iran, Iraq, Morocco, and Turkey. Attackers exploited a Samsung-specific zero-day vulnerability using malicious DNG image files, often distributed via WhatsApp, enabling zero-click infection without user interaction. Once compromised, Landfall enables extensive surveillance capabilities, such as microphone activation and unauthorized data collection—including contacts and photos. While attribution remains inconclusive, similarities in infrastructure hint at possible links to the Stealth Falcon APT group.
This incident highlights the rising use of zero-click exploits and highly-targeted mobile spyware attacks against consumer devices. The sophistication and persistence of such campaigns are forcing device vendors, regulators, and enterprises to invest in rapid patching, threat detection, and zero trust mobile security strategies to counter fast-evolving mobile threats.
Why This Matters Now
The Landfall spyware campaign underscores an urgent trend: the proliferation of untraceable, zero-click threats targeting widely used consumer devices in geopolitically tense regions. Businesses and users should act now to mitigate exposure, as advanced attackers increasingly leverage mobile platform vulnerabilities before patches are available, raising regulatory, privacy, and national security concerns.
Attack Path Analysis
Attackers exploited a Samsung-specific zero-day in image processing to deliver Landfall spyware through malicious DNG files sent via WhatsApp, successfully compromising targeted Galaxy devices. Following compromise, the spyware leveraged its foothold to escalate privileges for persistent access and broad device control. Lateral movement within the device allowed the implant to access sensitive data and system resources, remaining hidden from detection. The malware established command and control by covertly communicating with attacker infrastructure to receive instructions and exfiltrate collected data. Sensitive data such as photos, contacts, and microphone recordings were exfiltrated to external servers. The impact included unauthorized surveillance, privacy breaches, and potential long-term device compromise for high-value targets.
Kill Chain Progression
Initial Compromise
Description
Attackers delivered malicious DNG image files via WhatsApp exploiting a zero-click Samsung-specific image processing vulnerability, resulting in initial spyware installation with no user interaction.
Related CVEs
CVE-2025-21042
CVSS 8.8An out-of-bounds write vulnerability in Samsung's image processing library libimagecodec.quram.so allows remote code execution via malicious DNG image files.
Affected Products:
Samsung Galaxy S22 – 13, 14, 15
Samsung Galaxy S23 – 13, 14, 15
Samsung Galaxy S24 – 13, 14, 15
Samsung Galaxy Z Fold 4 – 13, 14, 15
Samsung Galaxy Z Flip 4 – 13, 14, 15
Exploit Status:
exploited in the wildCVE-2025-21043
CVSS 8.8An out-of-bounds write vulnerability in Samsung's image processing library libimagecodec.quram.so allows remote code execution via crafted image files.
Affected Products:
Samsung Galaxy S22 – 13, 14, 15
Samsung Galaxy S23 – 13, 14, 15
Samsung Galaxy S24 – 13, 14, 15
Samsung Galaxy Z Fold 4 – 13, 14, 15
Samsung Galaxy Z Flip 4 – 13, 14, 15
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Upload Malware
Application or OS Exploitation: Mobile OS Exploitation
Input Capture: Credential API Hooking
Broadcast Receivers
Capture Camera
Audio Capture
Location Tracking
Download New Code at Runtime
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Respond to and Manage Incidents
Control ID: 12.10.5
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 10
NIS2 Directive – Risk Management and Security of Network and Information Systems
Control ID: Article 21(2)b,d
CISA Zero Trust Maturity Model (ZTMM) 2.0 – Device Security – Continuous Monitoring and Threat Detection
Control ID: Device Pillar – Continuous Monitoring
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Mobile spyware targeting Middle East creates critical risks for government officials, requiring enhanced zero trust segmentation and threat detection capabilities.
Defense/Space
Zero-click Samsung Galaxy exploits pose severe operational security threats, necessitating encrypted communications and comprehensive mobile device management protocols.
Telecommunications
WhatsApp-delivered spyware campaigns threaten communication infrastructure integrity, demanding robust egress security and anomaly detection systems for network protection.
Oil/Energy/Solar/Greentech
Regional energy sector faces targeted surveillance risks through mobile devices, requiring multicloud visibility and east-west traffic security implementations.
Sources
- New Landfall spyware apparently targeting Samsung phones in Middle Easthttps://cyberscoop.com/landfall-spyware-samsung-phones-palo-alto-networks-unit-42/Verified
- ‘Landfall’ spyware abused zero-day to hack Samsung Galaxy phoneshttps://techcrunch.com/2025/11/07/landfall-spyware-abused-zero-day-to-hack-samsung-galaxy-phones/Verified
- Commercial spyware 'Landfall' ran rampant on Samsung phones for almost a yearhttps://arstechnica.com/gadgets/2025/11/commercial-spyware-landfall-ran-rampant-on-samsung-phones-for-almost-a-year/Verified
- Samsung patches actively exploited zero-day Android flawhttps://www.scworld.com/news/samsung-patches-actively-exploited-zero-day-android-flawVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing network microsegmentation, egress security, advanced anomaly detection, and encrypted network traffic controls at the connectivity and cloud perimeter level would have limited the spyware’s capability to maintain command and control, exfiltrate sensitive data, or move laterally within the affected environment even after device compromise.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Attack traffic attempting to exploit cloud-exposed surfaces can be detected and flagged.
Control: Threat Detection & Anomaly Response
Mitigation: Abnormal privilege escalation behaviors can trigger alerts to incident responders.
Control: Zero Trust Segmentation
Mitigation: Microsegmentation restricts unauthorized movement to critical workloads.
Control: Egress Security & Policy Enforcement
Mitigation: Suspicious outbound traffic to C2 domains can be blocked or monitored.
Control: Encrypted Traffic (HPE) & Egress Security
Mitigation: Unauthorized data exfiltration attempts are flagged, blocked, or encrypted for confidentiality.
Centralized monitoring and policy enforcement limit the operational effectiveness of long-term implants.
Impact at a Glance
Affected Business Functions
- Communications
- Data Management
- Security Operations
Estimated downtime: 7 days
Estimated loss: $5,000,000
Potential exposure of sensitive user data including photos, messages, contacts, and call logs due to spyware infection.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce granular east-west microsegmentation and zero trust policies to restrict malware movement within managed environments.
- • Deploy robust egress security controls and inline inspection to detect, block, and alert on suspicious outbound and command-and-control communications.
- • Invest in anomaly-based threat detection to surface privilege escalation and covert malware operations, with continuous visibility across cloud and device edges.
- • Ensure encrypted traffic oversight (line-rate encryption, MACsec/IPsec) to protect data in transit and identify unauthorized data exfiltration attempts.
- • Regularly update zero-day and threat signature libraries in CNSF platforms to enhance real-time detection and automated threat response.



