{"id":8513,"date":"2025-11-08T05:46:08","date_gmt":"2025-11-08T05:46:08","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=8513"},"modified":"2025-11-08T05:46:08","modified_gmt":"2025-11-08T05:46:08","slug":"samsung-zero-day-flaw-exploited-by-landfall-adware","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=8513","title":{"rendered":"Samsung Zero-Day Flaw Exploited by &#8216;Landfall&#8217; Adware"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"generic-article\">\n<p class=\"text-muted\">\n                                            <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/cyberwarfare-nation-state-attacks-c-420\" id=\"asset_topic_1_1\">Cyberwarfare \/ Nation-State Assaults<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/endpoint-security-c-506\" id=\"asset_topic_1_2\">Endpoint Safety<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/fraud-management-cybercrime-c-409\" id=\"asset_topic_1_3\">Fraud Administration &amp; Cybercrime<\/a>\n                                                    <\/p>\n<p>                    <span class=\"article-sub-title\">Adware Targets Samsung Galaxy Gadgets, Says Unit 42<\/span><br \/>\n                <span class=\"article-byline\"><br \/>\n                                                <a rel=\"nofollow\" target=\"_blank\" class=\"author-link\" href=\"https:\/\/www.bankinfosecurity.com\/authors\/greg-sirico-i-7198\">Greg Sirico<\/a>                                                     \u2022<br \/>\n                        <span class=\"text-nowrap\">November 7, 2025<\/span> \u00a0 \u00a0 <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/samsung-zero-day-flaw-exploited-by-landfall-spyware-a-29963#disqus_thread\"\/><\/span><\/p>\n<figure>\n                <img decoding=\"async\" src=\"https:\/\/ismg-cdn.nyc3.cdn.digitaloceanspaces.com\/articles\/samsung-zero-day-flaw-exploited-by-landfall-spyware-image_large-8-a-29963.jpg\" alt=\"Samsung Zero-Day Flaw Exploited by 'Landfall' Spyware\" class=\"img-responsive \"\/><figcaption>Samsung Galaxy fashions focused with the malware embody the Galaxy S23 Collection, Galaxy S24 Collection, Galaxy S22, Galaxy Z Flip4 and Galaxy Z Fold4, pictured. (Picture: Shutterstock)<\/figcaption><\/figure>\n<p>Hackers used beforehand unknown business spy ware to surveil the actions of Samsung Galaxy machine house owners within the Center East, say safety researchers who posit the menace actor has connections to the United Arab Emirates.<\/p>\n<p><b>See Additionally:<\/b> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.net\/whitepapers\/5-ways-exabeam-helps-eliminate-compromised-credential-blindspots-w-10986?rf=RAM_SeeAlso\">5 Methods Exabeam Helps Remove Compromised Credential Blindspots<\/a><\/p>\n<p>Researchers from Palo Alto Networks Unit 42 on Friday <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/unit42.paloaltonetworks.com\/landfall-is-new-commercial-grade-android-spyware\" target=\"_blank\">disclosed<\/a> spy ware they dub &#8220;Landfall,&#8221; writing that the producer <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb?year=2025&amp;month=04\" target=\"_blank\">patched<\/a> it in April. Tracked as <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-21042\" target=\"_blank\">CVE-2025-21042<\/a>, the flaw let hackers embed malware right into a <a rel=\"nofollow\" target=\"_blank\" href=\" https:\/\/www.adobe.com\/creativecloud\/file-types\/image\/raw\/dng-file.html\" target=\"bl;ank\">DNG picture<\/a> file, presumably texted to the sufferer via WhatsApp.<\/p>\n<p>It seems that machine infections did not require consumer interplay after hackers despatched the corrupted picture &#8211; constituting what&#8217;s often known as a zero-click assault. <\/p>\n<p>Unit 42 would not attribute the malware to any specific actor, however researchers did discover similarities between Landfall&#8217;s command and management infrastructure and area registration patterns and infrastructure related to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/groups\/G0038\/\" target=\"_blank\">Stealth Falcon<\/a>, a menace actor that&#8217;s at the very least circumstantially related to the UAE authorities.<\/p>\n<p>Builders of the spy ware could be Variston, a Barcelona-based vendor that <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/techcrunch.com\/2025\/02\/13\/barcelona-based-spyware-startup-variston-reportedly-shuts-down\/\" target=\"_blank\">reportedly<\/a> shut down earlier this yr. Unit 42 once more wrote that it will probably&#8217;t make certain, however stated evaluation of spy ware elements recommend a hyperlink to Variston, which has equipped tooling to UAE purchasers.<\/p>\n<p>As soon as a tool has been contaminated, Landfall basically turns into a surveillance hub. The spy ware is able to microphone recording, location monitoring and exfiltrating private information along with stealing pictures, contacts and name logs. <\/p>\n<p>Unit 42 stated it probed the flaw after Apple in August patched an identical flaw for iOS gadgets. That flaw, tracked as <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-43300\" target=\"_blank\">CVE-2025-43300<\/a>, additionally exploited cellular operation system processing of DNG photos.<\/p>\n<p>&#8220;We can not affirm whether or not this chain was used to ship an equal of Landfall to iOS, or whether or not it&#8217;s the identical menace actor behind the 2. Nevertheless, this parallel improvement within the iOS ecosystem, mixed with the disclosure of the Samsung and Apple vulnerabilities just some weeks aside, highlights a broader sample of DNG picture processing vulnerabilities being leveraged in subtle cellular spy ware assaults,&#8221; researchers wrote.<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Cyberwarfare \/ Nation-State Assaults , Endpoint Safety , Fraud Administration &amp; Cybercrime Adware Targets Samsung Galaxy Gadgets, Says Unit 42 Greg Sirico \u2022 November 7, 2025 \u00a0 \u00a0 Samsung Galaxy fashions focused with the malware embody the Galaxy S23 Collection, Galaxy S24 Collection, Galaxy S22, Galaxy Z Flip4 and Galaxy Z Fold4, pictured. (Picture: Shutterstock) [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":8515,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[1994,2705,4955,2490,1724,4218],"class_list":["post-8513","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-exploited","tag-flaw","tag-landfall","tag-samsung","tag-spyware","tag-zeroday"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/8513","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8513"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/8513\/revisions"}],"predecessor-version":[{"id":8514,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/8513\/revisions\/8514"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/8515"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8513"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8513"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8513"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-27 00:56:29 UTC -->