PULSE NAME
New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices
WHITE AlienVault 2025-11-07 Modified: 2025-12-07
17
IOCs
MEDIUM VOLUME
Unit 42 researchers have uncovered LANDFALL, a previously unknown Android spyware family targeting Samsung Galaxy devices. The spyware exploits CVE-2025-21042, a zero-day vulnerability in Samsung's image processing library, to deliver commercial-grade surveillance capabilities. LANDFALL is embedded in malicious DNG image files, likely distributed via WhatsApp, and enables comprehensive monitoring including microphone recording, location tracking, and data collection. The campaign shares infrastructure with known commercial spyware operations in the Middle East. The vulnerability has been patched, but the exploit chain remained active and undetected for months before discovery.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (17)
All FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 211311468f3673f005031d5f77d4d716e80cbf3c1f0bb1f148f2200920513261 2025-11-07
FileHash-SHA256 2425f15eb542fca82892fd107ac19d63d4d112ddbfe698650f0c25acf6f8d78a 2025-11-07
FileHash-SHA256 29882a3c426273a7302e852aa77662e168b6d44dcebfca53757e29a9cdf02483 2025-11-07
FileHash-SHA256 384f073d3d51e0f2e1586b6050af62de886ff448735d963dfc026580096d81bd 2025-11-07
FileHash-SHA256 69cf56ac6f3888efa7a1306977f431fd1edb369a5fd4591ce37b72b7e01955ee 2025-11-07
FileHash-SHA256 9297888746158e38d320b05b27b0032b2cc29231be8990d87bc46f1e06456f93 2025-11-07
FileHash-SHA256 a62a2400bf93ed84ebadf22b441924f904d3fcda7d1507ba309a4b1801d44495 2025-11-07
FileHash-SHA256 b06dec10e8ad0005ebb9da24204c96cb2e297bd8d418bc1c8983d066c0997756 2025-11-07
FileHash-SHA256 b45817ffb0355badcc89f2d7d48eecf00ebdf2b966ac986514f9d971f6c57d18 2025-11-07
FileHash-SHA256 b975b499baa3119ac5c2b3379306d4e50b9610e9bba3e56de7dfd3927a96032d 2025-11-07
FileHash-SHA256 c0f30c2a2d6f95b57128e78dc0b7180e69315057e62809de1926b75f86516b2e 2025-11-07
FileHash-SHA256 d2fafc7100f33a11089e98b660a85bd479eab761b137cca83b1f6d19629dd3b0 2025-11-07
FileHash-SHA256 ffeeb0356abb56c5084756a5ab0a39002832403bca5290bb6d794d14b642ffe2 2025-11-07
domain brightvideodesigns.com 2025-11-07
domain healthyeatingontherun.com 2025-11-07
domain hotelsitereview.com 2025-11-07
domain projectmanagerskills.com 2025-11-07