TF-MAL-apk.landfall
📛 Threat Title
Malware family: LANDFALL
Description
ThreatFox malware family `apk.landfall`. Printable name: LANDFALL.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.landfall
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.landfall
IOC database
- Type
- domain
- Value
apk.landfall- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.landfall
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.landfall
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:arstechnica.com
Commercial spyware " Landfall " ran rampant on Samsung phones for almost a year Targeted attack could steal all of a phone's data and activate camera or mic.
-
web:insights.integrity360.com
LANDFALL is a previously undocumented Android spyware family observed targeting Samsung Galaxy devices via malformed DNG (Digital Negative) image files. The campaign exploited CVE-2025-21042, a zero-day in Samsung's image-processing library, to achieve remote code execution—likely with a zero-click path when images were received over WhatsApp.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the LANDFALL malware family including references, samples and yara signatures.
-
web:securityonline.info
Researchers from Unit 42, the threat intelligence team at Palo Alto Networks, have discovered a previously unknown Android spyware family dubbed LANDFALL , which leveraged a zero-day vulnerability (CVE-2025-21042) in Samsung's image processing library to compromise Galaxy devices. The campaign—active since mid-2024—appears to have targeted users in the Middle East, with the spyware ...
-
web:techcrunch.com
Unit 42 said that the Landfall spyware samples that they discovered had been uploaded to VirusTotal, a malware scanning service, from individuals in Morocco, Iran, Iraq, and Turkey throughout 2024 ...
-
web:thehackernews.com
A now-patched security flaw in Samsung Galaxy Android devices was exploited as a zero-day to deliver a "commercial-grade" Android spyware dubbed LANDFALL in targeted attacks in the Middle East. The activity involved the exploitation of CVE-2025-21042 (CVSS score: 8.8), an out-of-bounds write flaw in ...
-
web:unit42.paloaltonetworks.com
Commercial-grade LANDFALL spyware exploits CVE-2025-21042 in Samsung Android's image processing library. The spyware was embedded in malicious DNG files.
-
web:www.pcmag.com
A cybersecurity vendor uncovers more details about how a spyware attack exploited a serious flaw in Samsung's software for months to target select users.
-
web:www.pcrisk.com
What kind of malware is Landfall ? Landfall is Android spyware targeting Samsung Galaxy devices (mainly in the Middle East). It is capable of recording audio, tracking location, and accessing photos, contacts, and call logs. The malware spreads via malicious DNG image files by exploiting a vulnerability in Samsung's image processing library.
-
web:www.rescana.com
A sophisticated Android spyware campaign leveraging the newly discovered LANDFALL malware has been identified targeting users of Samsung Galaxy devices. This campaign exploits a critical zero-day vulnerability, CVE-2025-21042, in the Samsung image processing library, libimagecodec.quram.so, enabling remote code execution via malicious DNG (Digital Negative) image files. The attack vector is ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.