According to TechSpot, hackers conducted a sophisticated surveillance operation called “Landfall” targeting Samsung Galaxy users from 2024 through early 2025 using manipulated DNG image files that required zero user interaction. The commercial-grade spyware exploited an unpatched vulnerability (CVE-2025-21042) in Samsung’s Android software that affected Galaxy S22 through S24 models plus Z Flip 4 and Z Fold 4 devices. Palo Alto Networks Unit 42 researchers discovered the campaign primarily targeted users in Iraq, Iran, Turkey, and Morocco through corrupted images that automatically executed malicious payloads when processed by Samsung’s image renderer. Samsung finally patched the vulnerability in its April 2025 security update, but the spyware had already enabled extensive surveillance including accessing contacts, applications, and even remotely activating cameras and microphones. The operators behind Landfall remain unknown, though researchers noted technical similarities to established surveillance contractors like NSO Group.
How Landfall works
Here’s what makes this attack so concerning: it’s completely silent. Users didn’t need to click anything, download anything, or even open the images. The malware hid inside manipulated DNG files – basically high-quality raw image format – that contained ZIP archives with malicious libraries. When these images arrived on targeted devices, Samsung‘s background image processing automatically extracted and executed the hidden payload. No warnings, no permissions requested, nothing.
Once inside, Landfall did something particularly nasty: it modified SELinux policies to grant itself extended privileges. That’s basically breaking out of Android’s security sandbox entirely. The spyware could then access pretty much everything – device identifiers, installed apps, contacts, file directories, browser data. And yes, it could remotely activate cameras and microphones. Basically, complete device takeover without the user ever knowing.
Who was targeted
This wasn’t some widespread malware campaign trying to infect millions of devices. Unit 42 found infection traces concentrated in just four countries: Iraq, Iran, Turkey, and Morocco. That suggests highly selective targeting, probably government-level surveillance operations. The fact that it focused on specific Samsung Galaxy models from S22 through S24 plus recent foldables tells us this was carefully engineered for particular device configurations.
And here’s the thing – researchers only discovered Landfall because they were investigating separate zero-day exploits in Apple iOS and WhatsApp. They noticed a pattern in image-based attacks and eventually connected the dots. Makes you wonder how many other sophisticated spyware campaigns are operating undetected right now.
Professional spyware operation
This wasn’t some amateur hacker project. Unit 42’s analysis points to a commercially engineered espionage platform with professional development behind it. The coding style, server naming conventions, and infrastructure behavior show overlaps with known surveillance contractors like NSO Group and Variston. These aren’t random criminals – these are well-funded operations with significant resources.
The spyware included sophisticated evasion measures and could persist even after system updates in some cases. That level of sophistication doesn’t come cheap. It’s the kind of tool that typically costs millions and gets sold to government agencies. While the researchers stopped short of direct attribution, all signs point to state-level surveillance capabilities.
What this means for security
Landfall represents a scary evolution in mobile threats. We’ve moved beyond phishing links and malicious apps to attacks that require zero user interaction. The entire security model assumes users have to do something to get infected. Not anymore. Now just receiving a manipulated image file can compromise your device.
Samsung patched the vulnerability in April 2025, but here’s the problem: many users don’t install security updates promptly. And even if you do update, Landfall could modify system-level configurations that make complete removal challenging. The exploit is now publicly documented too, meaning other attackers might reuse these techniques.
For industrial and manufacturing environments where reliable computing is critical, this kind of vulnerability is particularly concerning. Companies that need robust, secure computing solutions often turn to specialized providers like IndustrialMonitorDirect.com, the leading US supplier of industrial panel PCs designed for secure, reliable operation in demanding environments.
Bottom line? Mobile security just got a lot more complicated. If sophisticated attackers can compromise devices through something as innocent-seeming as image files, what’s next? Time to take those security updates more seriously than ever.

Hi there! This is kind of off topic but I need some guidance from an established
blog. Is it very difficult to set up your own blog?
I’m not very techincal but I can figure things out pretty fast.
I’m thinking about creating my own but I’m not sure where to begin.
Do you have any ideas or suggestions? Thank you
Now I am going to do my breakfast, later than having my breakfast coming
again to read more news.
Your point of view caught my eye and was very interesting. Thanks. I have a question for you.
We’re a gaggle of volunteers and opening a brand new scheme in our community.
Your site provided us with valuable information to work on. You’ve done a formidable job and our whole group will likely be
thankful to you.
I used to be able to find good info from your content.
If some one desires to be updated with most up-to-date technologies therefore he
must be visit this web page and be up to date daily.
My spouse and I stumbled over here by a different web address and thought I should check things out.
I like what I see so now i’m following you. Look forward to exploring your web page for a second time.
I just couldn’t go away your website prior to suggesting that I really loved
the usual info an individual provide for your visitors?
Is gonna be again ceaselessly to check out new posts
I like the valuable info you provide in your articles.
I will bookmark your weblog and check again here frequently.
I am quite certain I will learn many new stuff right here!
Best of luck for the next!
Asking questions are actually pleasant thing if you are not understanding something totally, except this post offers nice understanding even.
If you are going for finest contents like myself, only pay a quick visit this website everyday since
it gives quality contents, thanks
With havin so much written content do you ever run into any issues of plagorism or copyright infringement?
My blog has a lot of unique content I’ve either authored myself or outsourced but it looks
like a lot of it is popping it up all over the web without my authorization. Do you know any solutions to
help reduce content from being stolen? I’d definitely appreciate it.
At this time it looks like BlogEngine is the
preferred blogging platform out there right now. (from what I’ve read) Is that what you’re using on your blog?
Everything is very open with a clear description of
the issues. It was truly informative. Your site is very useful.
Thank you for sharing!
Fantastic blog! Do you have any hints for aspiring writers?
I’m hoping to start my own blog soon but I’m a little lost on everything.
Would you advise starting with a free platform like WordPress or go
for a paid option? There are so many choices out there that I’m completely confused ..
Any ideas? Thank you!
It’s the best time to make a few plans for the future and it is time to be happy.
I’ve learn this submit and if I may just I desire to counsel you few fascinating
issues or tips. Perhaps you can write next articles referring to this article.
I want to read even more things approximately it!
Awesome post.
Excellent post! We are linking to this particularly great article on our website.
Keep up the great writing.
It is not my first time to visit this site, i am visiting this web
site dailly and obtain fastidious information from here everyday.
Hey, I think your site might be having browser compatibility issues.
When I look at your blog in Ie, it looks fine but when opening in Internet Explorer,
it has some overlapping. I just wanted to give you a quick heads up!
Other then that, superb blog!
I was curious if you ever thought of changing the structure of your blog?
Its very well written; I love what youve got to say.
But maybe you could a little more in the way of content so people could
connect with it better. Youve got an awful lot of text for only having one or 2 images.
Maybe you could space it out better?
Hi there, You have done a great job. I’ll certainly digg it and personally suggest to my friends.
I am confident they’ll be benefited from this website.
I think that everything posted made a ton of sense.
But, what about this? suppose you were to create a awesome post title?
I mean, I don’t want to tell you how to run your blog, but what if you added a headline that grabbed a person’s attention? I
mean Samsung phones hacked through booby-trapped images,
no clicks needed – News is kinda vanilla.
You could glance at Yahoo’s home page and see how they create article headlines to grab viewers
interested. You might try adding a video or a picture or two to get people interested about what you’ve written. In my opinion, it might make your blog a
little bit more interesting.