New Delhi: Samsung Galaxy users were unknowingly exposed to a months-long hacking campaign that silently targeted their phones and extracted sensitive data, all without a single tap. Security researchers at Palo Alto Networks Unit 42 have revealed a sophisticated Android spyware operation, dubbed Landfall, that exploited a zero-day flaw in Samsung’s software for nearly 10 months, from July 2024 to April 2025. Landfall took advantage of a previously unknown vulnerability, CVE-2025-21042, allowing the attackers to hijack a device simply by sending a specially crafted image, likely through messaging applications.
The victim didn’t need to click anything for the hack to work, making it a classic zero-click attack. Samsung eventually patched the flaw in April 2025, but until now, the scale and nature of the exploit have not been made public. Once installed, the spyware could report access to a wide range of personal data like Photos, Messages, Contacts, Call Logs, and Precise Location—and the Device microphone for real-time audio. Researchers say the spyware targeted specific Samsung models, including the Galaxy S22, S23, S24 and select Galaxy Z series devices. Android versions 13 through 15 are believed to have been affected.
Unit 42 emphasised that this wasn’t a widespread malware campaign but a precision attack aimed at the selected individuals, likely for surveillance or intelligence gathering. Unit 42 also found infrastructure overlaps with the known surveillance group called Stealth Falcon, previously linked to attacks on journalists and activists. The evidence was not strong enough to attribute the operation to any specific government. Samsung has not issued a statement regarding the findings. Researchers also noted that it remains unclear who built the spyware and how many people were actually targeted. Users with Galaxy devices running Android 13-15 are advised to ensure they have installed all April 2025 or later security updates.









