Executive Summary
In early 2024, cybersecurity researchers identified that a sophisticated threat actor exploited a zero-day vulnerability in Samsung’s Android image processing library to deploy a previously unknown spyware, dubbed 'LandFall.' The attackers delivered malicious images via WhatsApp messages, abusing the image parsing process to gain device access without user interaction. Once installed, LandFall enabled covert surveillance, exfiltration of private data, and remote control capabilities, putting millions of Samsung devices at risk globally—especially given the attack’s stealthy, user-independent execution method. The breach demonstrates a significant advancement in mobile spyware delivery and a major supply chain risk for mobile OS providers.
This incident is highly relevant as attackers increasingly leverage messaging platforms and zero-click vulnerabilities to distribute advanced spyware. The weaponization of zero-days against widespread consumer hardware underscores the urgent need for rapid vulnerability detection and robust response protocols across the mobile ecosystem.
Why This Matters Now
This breach highlights the growing sophistication of spyware, leveraging zero-click vulnerabilities and popular messaging applications to bypass user defenses. The urgent issue is the increased exploitation of unpatched zero-days in consumer devices, potentially compromising user privacy at scale before countermeasures can be implemented.
Attack Path Analysis
The attack began when the threat actor sent a malicious image over WhatsApp, exploiting a zero-day in Samsung's Android image processing to compromise the device. Escalating privileges, the spyware gained enhanced access to device and user data. It then performed lateral movement across local applications and potentially the cloud environment. Once embedded, LandFall established command and control communication to receive instructions from the attacker. The spyware exfiltrated sensitive information over external channels. Finally, the impact included unauthorized surveillance and data theft, with possible privacy and compliance violations.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited a zero-day vulnerability in Samsung's image processing via a malicious WhatsApp message to deliver and execute the LandFall spyware.
Related CVEs
CVE-2025-21042
CVSS 8.8An out-of-bounds write vulnerability in Samsung's libimagecodec.quram.so library allows remote code execution via malicious DNG image files.
Affected Products:
Samsung Galaxy S22 – 13, 14, 15
Samsung Galaxy S23 – 13, 14, 15
Samsung Galaxy S24 – 13, 14, 15
Samsung Galaxy Z Fold4 – 13, 14, 15
Samsung Galaxy Z Flip4 – 13, 14, 15
Exploit Status:
exploited in the wildCVE-2025-21043
CVSS 8.8An out-of-bounds write vulnerability in Samsung's libimagecodec.quram.so library allows remote code execution via crafted image files.
Affected Products:
Samsung Galaxy S22 – 13, 14, 15
Samsung Galaxy S23 – 13, 14, 15
Samsung Galaxy S24 – 13, 14, 15
Samsung Galaxy Z Fold4 – 13, 14, 15
Samsung Galaxy Z Flip4 – 13, 14, 15
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
User Execution: Malicious File
Exploit Public-Facing Application
Event Triggered Execution: Image File Execution Options Injection
Masquerading
Command and Scripting Interpreter
Input Capture
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of System Components
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 9
CISA Zero Trust Maturity Model 2.0 – Application Threat and Vulnerability Management
Control ID: Applications: Vulnerability Management
NIS2 Directive – Technical and Organisational Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
WhatsApp-delivered spyware exploiting Samsung zero-days creates severe risks for telecom infrastructure, requiring enhanced encrypted traffic monitoring and east-west segmentation controls.
Financial Services
Mobile spyware targeting Samsung devices threatens financial data integrity, demanding robust anomaly detection and egress security to prevent data exfiltration attacks.
Health Care / Life Sciences
LandFall spyware via messaging platforms risks HIPAA compliance violations, necessitating comprehensive threat detection and zero trust segmentation for patient data protection.
Government Administration
Zero-day exploits through popular messaging apps pose national security threats, requiring multicloud visibility controls and inline IPS deployment for sensitive communications.
Sources
- New LandFall spyware exploited Samsung zero-day via WhatsApp messageshttps://www.bleepingcomputer.com/news/security/new-landfall-spyware-exploited-samsung-zero-day-via-whatsapp-messages/Verified
- Samsung patches zero-day security flaw used to hack into its customers' phoneshttps://techcrunch.com/2025/09/16/samsung-patches-zero-day-security-flaw-used-to-hack-into-its-customers-phones/Verified
- Samsung Mobile Flaw Exploited as Zero-Day to Deploy LANDFALL Android Spywarehttps://thehackernews.com/2025/11/samsung-zero-click-flaw-exploited-to.htmlVerified
- Samsung Galaxy Zero-Day (CVE-2025-21042) Exploited to Deploy LANDFALL Android Spyware via WhatsApp DNG Imageshttps://www.rescana.com/post/samsung-galaxy-zero-day-cve-2025-21042-exploited-to-deploy-landfall-android-spyware-via-whatsapp-dVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Effective deployment of CNSF controls—including Zero Trust Segmentation, east-west enforcement, egress policy, inline threat detection, and centralized visibility—would have limited initial malware execution, prevented lateral movement, detected C2 activity, and blocked unauthorized exfiltration of sensitive data.
Control: Inline IPS (Suricata)
Mitigation: Detected and blocked known exploit signatures in real time.
Control: Zero Trust Segmentation
Mitigation: Minimized post-compromise privilege access through identity-based segmentation.
Control: East-West Traffic Security
Mitigation: Blocked lateral movement between workloads and sensitive resources.
Control: Egress Security & Policy Enforcement
Mitigation: Prevented or flagged suspicious outbound C2 communications.
Control: Encrypted Traffic (HPE) & Egress Security
Mitigation: Detected or blocked exfiltration attempts and secured data in transit.
Enabled rapid incident detection and response to contain business impact.
Impact at a Glance
Affected Business Functions
- Mobile Communications
- Data Security
- User Privacy
Estimated downtime: 7 days
Estimated loss: $5,000,000
Potential exposure of sensitive user data including photos, contacts, call logs, SMS messages, and location information due to spyware infection.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust Segmentation to limit attacker access following initial compromise.
- • Deploy inline IPS to detect and block exploitation attempts and known malicious payloads across ingress points.
- • Apply east-west traffic enforcement to prevent lateral pivoting between applications and workloads.
- • Implement strict egress policies, FQDN filtering, and outbound traffic monitoring to detect and halt data exfiltration and C2 activity.
- • Improve centralized multicloud visibility and automated anomaly response to shorten detection and resolution windows.



