Moneycontrol PRO
HomeTechnologySamsung Galaxy phones were targeted using Android spyware for a year

Samsung Galaxy phones were targeted using Android spyware for a year

Security researchers have uncovered a powerful Android spyware called Landfall that secretly targeted Samsung Galaxy phones for nearly a year. The campaign exploited a zero-day flaw, affecting Galaxy S22, S23, S24, and Z models before Samsung patched it in April 2025.

November 08, 2025 / 20:16 IST
samsunggalaxy

For almost a year, a powerful spyware quietly targeted Samsung Galaxy smartphones without users realizing it. Security researchers at Palo Alto Networks’ Unit 42 have now revealed that the spyware, called “Landfall,” was part of a highly sophisticated hacking campaign that began in July 2024 and continued until April 2025, according to a report by TechCrunch.

The attackers behind Landfall found a way to break into Galaxy phones using a zero-day vulnerability — a security flaw that even Samsung didn’t know existed at the time. All it took was a single image, carefully designed to exploit the flaw, sent through a messaging app. Once delivered, the spyware could silently infect the phone — no clicks, no downloads, no warning signs.

Samsung eventually fixed the flaw, now listed as CVE-2025-21042, in an April 2025 software update. But by then, the hackers had already been active for months, secretly watching and listening through the targeted phones.

Researchers say it’s still unclear who built or deployed Landfall, but the signs point to a state-backed surveillance operation. It wasn’t random — only certain individuals were targeted, mostly in the Middle East. Unit 42 believes these were “precision attacks,” likely aimed at journalists, activists, or political figures.

Interestingly, the digital trail left behind by Landfall overlaps with that of Stealth Falcon, a known surveillance group accused of spying on Emirati dissidents and journalists since 2012. While the connection is not confirmed, the similarities suggest a shared origin or cooperation between the two.

Data uploaded to VirusTotal, a malware analysis platform, showed that infected devices came from Morocco, Iran, Iraq, and Turkey. Turkey’s national cyber team even flagged one of Landfall’s communication servers as malicious, suggesting the spyware may have actively targeted users in the country.

Once installed, Landfall could do nearly anything — access messages, photos, call logs, and contacts, or even turn on the microphone and track the phone’s location. Researchers found code that specifically mentioned Galaxy models like the S22, S23, S24, and some Z Fold and Flip devices, all running Android 13 through 15.

Samsung has not commented on the discovery. But the revelation highlights a worrying reality: even the world’s most popular phones can become silent instruments of surveillance — and users might never know until long after the attack has ended.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

MC Tech Desk Read the latest and trending tech news—stay updated on AI, gadgets, cybersecurity, software updates, smartphones, blockchain, space tech, and the future of innovation.
first published: Nov 8, 2025 08:16 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347