Skip to content
Landfall Spyware Targets Samsung Galaxy Phones Through Android Flaw; Millions At Risk

Landfall Spyware Targets Samsung Galaxy Phones Through Android Flaw; Millions At Risk

In.Mashable • November 10, 2025

In a major cybersecurity development, security researchers have uncovered a powerful new spyware strain named Landfall, which has reportedly targeted Samsung Galaxy devices through a previously unknown Android vulnerability. The months-long hacking campaign is believed to have primarily focused on victims in the Middle East, according to researchers at Unit 42, the cybersecurity division of Palo Alto Networks.

Landfall functions much like the notorious Pegasus spyware, operating as a “zero-click” exploit, meaning that targets did not need to open a file or link for their phones to be infected. Researchers said that simply receiving a maliciously crafted image via a messaging app was enough to compromise a user’s device.

The attack exploited a zero-day Android OS vulnerability, one that Samsung was unaware of at the time of the campaign. The spyware was capable of infiltrating popular Galaxy models, including the Galaxy S22, S23, S24, and certain Z-series foldable devices.

The vulnerability affected devices running Android versions 13 through 15, potentially putting millions of users at risk before Samsung issued a patch in April 2025. However, researchers noted that Landfall was first detected in July 2024 and that the campaign had been active since mid-2024.

According to Unit 42, Landfall is an advanced surveillance tool designed to extract extensive personal and system data from infected devices. Once deployed, it could access photos, call logs, lists, messages, microphone feeds, and location data.

While the creators of Landfall remain unidentified, the spyware’s infrastructure shares similarities with systems previously linked to a known vendor called Stealth Falcon, which has been associated with surveillance operations in the Middle East.

Investigators have yet to determine how many individuals were affected, but findings suggest that the campaign was highly targeted rather than widespread, pointing toward government- espionage efforts.

The spyware was reportedly used in precision attacks against select individuals across the Middle East, including journalists, activists, and dissidents, echoing tactics seen in earlier spyware operations dating back to 2012. “It wasn’t a mass-scale malware attack, but a focused intrusion campaign,” said Itay Cohen, senior researcher at Unit 42, in a briefing.

Interestingly, a similar exploit was patched by Apple in August 2025. Researchers indicated that Apple’s A19 and A19 Pro chips were vulnerable to a comparable zero-day chain, though there’s no confirmation that Landfall was involved. To strengthen defenses, Apple introduced a new security system called Memory Integrity Enforcement (MIE) for iPhone 17 models to counter advanced spyware like Pegasus.

Samsung addressed the exploited vulnerability in its April 2025 security update, advising users to keep their devices updated and disable fast charging temporarily if overheating or instability occurs.

The discovery of Landfall underscores the growing threat of state-grade spyware targeting both Android and iOS ecosystems, raising fresh concerns user privacy and digital surveillance worldwide.

Extracted Entities

Attack Types (1)

Companies (2)

Malware (2)

Platforms (2)