Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

FDA faucets Richard Pazdur as new CDER director after Tidmarsh’s resignation

November 12, 2025

7 Greatest Social Media Automation Instruments to Save Time in 2025

November 12, 2025

M-Tiba took 10 days to detect breach exposing 5m Kenyans’ well being data

November 12, 2025
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • FDA faucets Richard Pazdur as new CDER director after Tidmarsh’s resignation
  • 7 Greatest Social Media Automation Instruments to Save Time in 2025
  • M-Tiba took 10 days to detect breach exposing 5m Kenyans’ well being data
  • Sony Enters the PS5 Gaming Monitor World with a 27″ Display That Expenses Your DualSense Controller Whereas You Play
  • Dana Fuel Indicators Landmark MoU to Redevelop Main Fuel Fields in Syria, Together with Abu Rabah
  • Inside Korea’s 2026 Startup & SME Funds: AI Factories Surge, International Growth Funding Shrinks – KoreaTechDesk
  • Financial hardship pushes half of South Africa’s frontline staff to zero financial savings
  • How Uber appears to know the place you’re – even with restricted location permissions
Wednesday, November 12
NextTech NewsNextTech News
Home - Cybersecurity & Digital Rights - Samsung Zero-Click on Flaw Exploited to Deploy LANDFALL Android Adware by way of WhatsApp
Cybersecurity & Digital Rights

Samsung Zero-Click on Flaw Exploited to Deploy LANDFALL Android Adware by way of WhatsApp

NextTechBy NextTechNovember 7, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
Samsung Zero-Click on Flaw Exploited to Deploy LANDFALL Android Adware by way of WhatsApp
Share
Facebook Twitter LinkedIn Pinterest Email


Nov 07, 2025Ravie LakshmananCellular Safety / Vulnerability

A now-patched safety flaw in Samsung Galaxy Android units was exploited as a zero-day to ship a “commercial-grade” Android adware dubbed LANDFALL in focused assaults within the Center East.

The exercise concerned the exploitation of CVE-2025-21042 (CVSS rating: 8.8), an out-of-bounds write flaw within the “libimagecodec.quram.so” element that might permit distant attackers to execute arbitrary code, based on Palo Alto Networks Unit 42. The difficulty was addressed by Samsung in April 2025.

“This vulnerability was actively exploited within the wild earlier than Samsung patched it in April 2025, following reviews of in-the-wild assaults,” Unit 42 stated. Potential targets of the exercise, tracked as CL-UNK-1054, are positioned in Iraq, Iran, Turkey, and Morocco primarily based on VirusTotal submission information.

The event comes as Samsung disclosed in September 2025 that one other flaw in the identical library (CVE-2025-21043, CVSS rating: 8.8) had additionally been exploited within the wild as a zero-day. There isn’t any proof of this safety flaw being weaponized within the LANDFALL marketing campaign.

DFIR Retainer Services

It is assessed that the assaults concerned sending by way of WhatsApp malicious photographs within the type of DNG (Digital Unfavorable) information, with proof of LANDFALL samples going all the best way again to July 23, 2024. That is primarily based on DNG artifacts bearing names like “WhatsApp Picture 2025-02-10 at 4.54.17 PM.jpeg” and “IMG-20240723-WA0000.jpg.”

LANDFALL, as soon as put in and executed, acts as a complete spy instrument, able to harvesting delicate information, together with microphone recording, location, photographs, contacts, SMS, information, and name logs. The exploit chain is alleged to have possible concerned using a zero-click strategy to set off exploitation of CVE-2025-21042 with out requiring any person interplay.

1000031603
Flowchart for LANDFALL adware

It is price noting that across the identical time WhatsApp disclosed {that a} flaw in its messaging app for iOS and macOS (CVE-2025-55177, CVSS rating: 5.4) was chained together with CVE-2025-43300 (CVSS rating: 8.8), a flaw in Apple iOS, iPadOS, and macOS, to probably goal lower than 200 customers as a part of a complicated marketing campaign. Apple and WhatsApp have since patched the failings.

1000031615
Timeline for latest malicious DNG picture information and related exploit exercise

Unit 42’s evaluation of the found DNG information present that they arrive with an embedded ZIP file appended to the top of the file, with the exploit getting used to extract a shared object library from the archive to run the adware. Additionally current within the archive is one other shared object that is designed to govern the gadget’s SELinux coverage to grant LANDFALL elevated permissions and facilitate persistence.

CIS Build Kits

The shared object that masses LANDFALL additionally communicates with a command-and-control (C2) server over HTTPS to enter right into a beaconing loop and obtain unspecified next-stage payloads for subsequent execution.

It is presently not recognized who’s behind the adware or the marketing campaign. That stated, Unit 42 stated LANDFALL’s C2 infrastructure and area registration patterns dovetail with that of Stealth Falcon (aka FruityArmor), though, as of October 2025, no direct overlaps between the 2 clusters have been detected.

“From the preliminary look of samples in July 2024, this exercise highlights how refined exploits can stay in public repositories for an prolonged interval earlier than being totally understood,” Unit 42 stated.

Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the newest breakthroughs, get unique updates, and join with a worldwide community of future-focused thinkers.
Unlock tomorrow’s tendencies right now: learn extra, subscribe to our e-newsletter, and turn out to be a part of the NextTech neighborhood at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

How Uber appears to know the place you’re – even with restricted location permissions

November 12, 2025

Why software program patching issues greater than ever

November 11, 2025

Hackers Exploiting Triofox Flaw to Set up Distant Entry Instruments by way of Antivirus Characteristic

November 11, 2025
Add A Comment
Leave A Reply Cancel Reply

Economy News

FDA faucets Richard Pazdur as new CDER director after Tidmarsh’s resignation

By NextTechNovember 12, 2025

The FDA on Tues­day named lengthy­time can­cer chief Richard Paz­dur as di­rec­tor of the Cen­ter…

7 Greatest Social Media Automation Instruments to Save Time in 2025

November 12, 2025

M-Tiba took 10 days to detect breach exposing 5m Kenyans’ well being data

November 12, 2025
Top Trending

FDA faucets Richard Pazdur as new CDER director after Tidmarsh’s resignation

By NextTechNovember 12, 2025

The FDA on Tues­day named lengthy­time can­cer chief Richard Paz­dur as di­rec­tor…

7 Greatest Social Media Automation Instruments to Save Time in 2025

By NextTechNovember 12, 2025

Managing social media isn’t nearly posting, it’s about strategizing, planning and perfecting…

M-Tiba took 10 days to detect breach exposing 5m Kenyans’ well being data

By NextTechNovember 12, 2025

A cyberattack on M-Tiba, a Kenyan healthtech platform, went undetected for 10…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!