Skip to content
CYCRAFT
SECURING SESSION
CyCraft
Back to Blog
Malware21 Nov 2025

Commercial-Grade LANDFALL Spyware Exploits Zero-Day in Samsung Galaxy Phones

A commercial-grade Android spyware called LANDFALL exploited a Samsung Galaxy zero-day for nearly seven months delivered silently through WhatsApp images and attributed to a surveillance vendor in the Pegasus mould.

By EthicalByte7 min read

Newly Identified Android Spyware Linked to Commercial Vendor

A powerful Android spyware strain called LANDFALL has been uncovered targeting Samsung Galaxy devices through a previously unknown zero-day vulnerability. Researchers believe the malware originates from a commercial surveillance vendor due to its sophistication and operational structure.

How LANDFALL Infects Devices

The attackers exploited a zero-day flaw inside Samsung’s image processing libraries, used by Galaxy phones to render images. The infection chain began through malicious images sent over WhatsApp, where opening the image triggered the vulnerability and initiated the spyware installation.

  • Delivered through WhatsApp as seemingly normal images.
  • Triggered a flaw in the device’s media processing pipeline.
  • Installed spyware silently without any user interaction.
  • Exfiltrated contacts, messages, app data, and device metadata.

Likely Built by a Commercial Spyware Vendor

Investigators noted that LANDFALL does not resemble common criminal malware. Instead, it shows signs of being developed by an advanced surveillance vendor, similar to FinFisher, QuaDream, or NSO’s Pegasus frameworks.

Its modular structure, stealth, and exploit quality strongly indicate a state-level or commercial customer.

Zero-Day Fix Delayed for Months

The vulnerability was privately reported to Samsung in September 2024. However, a patch was not released until April 2025 nearly seven months later.

During this window, attackers had uninterrupted access to vulnerable Galaxy devices, allowing them to spy on selected targets across regions.

LANDFALLAndroid SpywareSamsungZero-DayMobile SecurityCommercial Malware

Interactions

18

Comments (0)

Anonymous