Cybersecurity experts uncovered Landfall on the Android side, an espionage tool that targeted Samsung Galaxy phones as part of an almost year-long cyber-espionage campaign.
Researchers from Palo Alto Networks’ Unit 42 reported that the Landfall malware was first detected in July 2024 and it exploited a zero-day vulnerability in Galaxy software, of which Samsung had only limited knowledge at the time.
The vulnerability could be exploited by sending the victim a maliciously crafted image, likely via a messaging app, and the attacks could occur even without user interaction.
Samsung patched the vulnerability – CVE-2025-21042 – in April 2025, but details of the Landfall campaign had not been disclosed earlier.
Researchers could not determine which surveillance vendor developed Landfall, or how many people could have been targeted; estimates suggest the attacks were likely aimed at individuals in the Middle East.
According to Itai Cohen of Unit 42, the campaign was a “precision strike” against specific individuals, not a mass-distributed malware.
«precision strike» against specific individuals, not mass-distributed malware.
Unit 42 also noted that Landfall samples were uploaded to VirusTotal by users from Morocco, Iran, Iraq, and Turkey during 2024 and in early 2025.
Turkey’s National Cyber Readiness Team USOM confirmed that one of the IP addresses Landfall connected from was considered malicious, underscoring a focus on Turkey.
Like many other government spyware tools, Landfall provides broad access to a device’s data: photos, messages, contacts, and call logs, as well as the ability to eavesdrop on the microphone and precisely track location.
Landfall samples contained references to five specific Galaxy phones – the S22, S23, S24, and some models of the Z series – and indicated the possibility of the vulnerability existing in other Galaxy devices and in Android versions 13–15. Samsung did not provide on this.
This intelligence underscores the seriousness of mobile spying tools and highlights the need to keep devices up to date with security updates and to exercise careful control over app permissions.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
