Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Hackers Breach Samsung Galaxy Phones Using A Single WhatsApp Image In Sophisticated Spyware Operation

post, november 8, 2025november 10, 2025

Security researchers at Palo Alto Networks Unit 42 have uncovered a sophisticated espionage campaign leveraging a zero-day vulnerability in select Samsung Galaxy Android devices. The flaw, tracked as CVE‑2025‑21042 (CVSS 8.8), is an out-of-bounds write defect in the libimagecodec.quram.so image-processing library, which could allow remote code execution. According to Unit 42, the flaw was exploited in the wild prior to the patch being issued by Samsung in April 2025.

The campaign centrepiece is a previously undocumented Android spyware family dubbed LANDFALL. The malicious chain begins with a malformed DNG (Digital Negative) image file, bearing filenames typical of WhatsApp transfers (e.g., “WhatsApp Image 2025-02-10 at 4.54.17 PM.jpeg” or “IMG-20240723-WA0000.jpg”). The image hides a ZIP payload appended to its end, which extracts shared-object libraries (.so) on the target device. One module manipulates SELinux policy to escalate privileges; another serves as the loader/backdoor.

Hackers Breach Samsung Galaxy Phones Using A Single WhatsApp Image In Sophisticated Spyware Operation | LinkedIn: Hackers Breach Samsung Galaxy Phones Using A Single WhatsApp Image In Sophisticated Spyware Operation
malware vulnerability 2025

Bericht navigatie

Previous post
Next post

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes