{"id":847,"date":"2025-11-08T10:06:26","date_gmt":"2025-11-08T08:06:26","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=847"},"modified":"2025-11-10T10:07:06","modified_gmt":"2025-11-10T08:07:06","slug":"hackers-breach-samsung-galaxy-phones-using-a-single-whatsapp-image-in-sophisticated-spyware-operation","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2025\/11\/08\/hackers-breach-samsung-galaxy-phones-using-a-single-whatsapp-image-in-sophisticated-spyware-operation\/","title":{"rendered":"Hackers Breach Samsung Galaxy Phones Using A Single WhatsApp Image In Sophisticated Spyware Operation"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\" id=\"ember57\">Security researchers at Palo Alto Networks Unit 42 have uncovered a <a href=\"https:\/\/unit42.paloaltonetworks.com\/landfall-is-new-commercial-grade-android-spyware\/\">sophisticated espionage campaign<\/a> leveraging a zero-day vulnerability in select Samsung Galaxy Android devices. The flaw, tracked as <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-21042\">CVE\u20112025\u201121042<\/a> (CVSS 8.8), is an out-of-bounds write defect in the libimagecodec.quram.so image-processing library, which could allow remote code execution. According to Unit 42, the flaw was exploited in the wild prior to the patch being issued by Samsung in April 2025.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ember58\">The campaign centrepiece is a previously undocumented Android spyware family dubbed <strong>LANDFALL<\/strong>. The malicious chain begins with a malformed DNG (Digital Negative) image file, bearing filenames typical of WhatsApp transfers (e.g., \u201cWhatsApp Image 2025-02-10 at 4.54.17 PM.jpeg\u201d or \u201cIMG-20240723-WA0000.jpg\u201d). The image hides a ZIP payload appended to its end, which extracts shared-object libraries (.so) on the target device. One module manipulates SELinux policy to escalate privileges; another serves as the loader\/backdoor.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2025\/11\/08\/hackers-breach-samsung-galaxy-phones-using-a-single-whatsapp-image-in-sophisticated-spyware-operation\/\" target=\"_self\"><a href=\"https:\/\/www.linkedin.com\/pulse\/hackers-breach-samsung-galaxy-phones-using-single-xvrke\/\">Hackers Breach Samsung Galaxy Phones Using A Single WhatsApp Image In Sophisticated Spyware Operation | LinkedIn<\/a><span class=\"screen-reader-text\">: Hackers Breach Samsung Galaxy Phones Using A Single WhatsApp Image In Sophisticated Spyware Operation<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>Security researchers at Palo Alto Networks Unit 42 have uncovered a sophisticated espionage campaign leveraging a zero-day vulnerability in select Samsung Galaxy Android devices. The flaw, tracked as CVE\u20112025\u201121042 (CVSS 8.8), is an out-of-bounds write defect in the libimagecodec.quram.so image-processing library, which could allow remote code execution. According to Unit&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,17],"tags":[40],"class_list":["post-847","post","type-post","status-publish","format-standard","hentry","category-malware","category-vulnerability","tag-40"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/847","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=847"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/847\/revisions"}],"predecessor-version":[{"id":848,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/847\/revisions\/848"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=847"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=847"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=847"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}