Samsung phones under threat from this dangerous new spyware cyberattack – here’s how to stay safe

  • CVE-2025-21042 flaw enabled remote code execution on multiple Samsung Galaxy devices
  • Attackers used WhatsApp to deliver LandFall spyware via malformed image files
  • Victims targeted in the Middle East; Stealth Falcon group suspected behind the campaign

Multiple Samsung Galaxy device series were vulnerable to a flaw that allowed threat actors to execute malicious code remotely, experts have warned.

To make matters worse, researchers are saying the flaw was used as a zero-day to target certain individuals in the Middle East with spyware and infostealers.

The bug, tracked as CVE-2025-21042 with a severity rating of 9.8/10 (critical) is described as an out-of-bounds write vulnerability, found in libimagecodec.quram.so prior to SMR Apr-2025 Release 1. Libimagecodec.quram.so is a shared library file that’s part of the image processing framework on Samsung Android devices.

Stealing files and recording audio

According to security researchers from Palo Alto Network’s Unit 42, the bug was used by a malicious entity to deploy the ‘LandFall’ spyware.

The attack includes dropping a malformed .DNG raw image format, with a .ZIP archive attached at the end of the file. The attack vector seems to have been WhatsApp, through which the file was shared.

After being deployed and executed, LandFall fingerprints the device it’s on, and analyzes all of the installed applications.

Its main capabilities include recording via microphone, call recording, location tracking, accessing contacts, SMS messages, call logs, files, and photos, and accessing browser history. It is also quite capable of avoiding being spotted and maintaining persistence on compromised devices.

Multiple Galaxy series of phones are said to be vulnerable: S22, S23, and S24, as well as Z Fold 4 and Z Flip 4. The newest Samsung flagship devices are apparently safe.

The victims seem to be located in Iraq, Iran, Turkey, and Morocco, while the attackers are most likely a group called Stealth Falcon, located in the United Arab Emirates (UAE). The researchers came to this conclusion by looking at LandFall’s C2 infrastructure. Palo Alto urges Samsung users to keep their devices updated and to be mindful of incoming messages, especially those with attachments of any kind.

Via BleepingComputer

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

You need to watch the modern horror masterpiece, His House

There's an argument to be made that "the real monster is trauma" has become an overused trope in modern horror. Hereditary, The Babadook, and,...

X cuts off the European Commission’s ad account after being fined €120 million

Friday, the EU slapped X with a €120 million fine (about $140 million) for violating the Digital Services Act (DSA). It was the first...

Netflix CEO made a visit to the White House before buying Warner Bros.

In November, Ted Sarandos, Netflix’s co-CEO made a trip to the White House for a lengthy meeting with Donald Trump. According to Bloomberg, the...

The Lord of the Rings trilogy returns to theaters in January for 25th anniversary

One does not simply spend more than 11 hours watching The Lord of the Rings trilogy in a single weekend at home when...

Apple’s AirPods Pro 3 drop to $230 on Amazon

If you haven't yet upgraded to Apple's AirPods Pro 3, you can pick up the company's latest model at a discount through a deal...

Looking for a Breville espresso machine? I’m a certified barista, and these are my 3 top recommendations

Breville is one of the biggest names in home coffee makers, and makes some of the best espresso machines I've tested here at TechRadar....

Good news, I found the cheapest large-capacity PCIe Gen4 SSD per TB – bad news, it will cost you more than $58,300

Solidigm's 61.44TB SSD offers lower cost per TB than any other large driveBulk purchases push the price below $95 per TB for 614TB of...

I bought a Kia EV6, my first electric car – here are 9 things I wish I’d known before buying an EV

When I bought my Kia EV6, I wasn’t planning on going electric. I’d rented a Tesla Model 3, and the experience was terrible. But...

X shuts down the European Commission’s ad account the day after major fine

Just a day after receiving a roughly $140 million fine, X has terminated the ad account of the European Commission. Nikita Bier, X's head...

OpenAI’s head of ChatGPT says posts appearing to show in-app ads are ‘not real or not ads’

Those might not exactly be ads you're seeing on ChatGPT, at least according to OpenAI. Nick Turley, OpenAI's head of ChatGPT, clarified the confusion...