s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.landfall

📛 Threat Title

Malware family: LANDFALL

Category: LANDFALL First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.landfall`. Printable name: LANDFALL.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.landfall VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.landfall

IOC database

Type
domain
Value
apk.landfall
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.landfall

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.landfall

References (1)

Remediations (10)

  • web:arstechnica.com

    Commercial spyware " Landfall " ran rampant on Samsung phones for almost a year Targeted attack could steal all of a phone's data and activate camera or mic.

  • web:insights.integrity360.com

    LANDFALL is a previously undocumented Android spyware family observed targeting Samsung Galaxy devices via malformed DNG (Digital Negative) image files. The campaign exploited CVE-2025-21042, a zero-day in Samsung's image-processing library, to achieve remote code execution—likely with a zero-click path when images were received over WhatsApp.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the LANDFALL malware family including references, samples and yara signatures.

  • web:securityonline.info

    Researchers from Unit 42, the threat intelligence team at Palo Alto Networks, have discovered a previously unknown Android spyware family dubbed LANDFALL , which leveraged a zero-day vulnerability (CVE-2025-21042) in Samsung's image processing library to compromise Galaxy devices. The campaign—active since mid-2024—appears to have targeted users in the Middle East, with the spyware ...

  • web:techcrunch.com

    Unit 42 said that the Landfall spyware samples that they discovered had been uploaded to VirusTotal, a malware scanning service, from individuals in Morocco, Iran, Iraq, and Turkey throughout 2024 ...

  • web:thehackernews.com

    A now-patched security flaw in Samsung Galaxy Android devices was exploited as a zero-day to deliver a "commercial-grade" Android spyware dubbed LANDFALL in targeted attacks in the Middle East. The activity involved the exploitation of CVE-2025-21042 (CVSS score: 8.8), an out-of-bounds write flaw in ...

  • web:unit42.paloaltonetworks.com

    Commercial-grade LANDFALL spyware exploits CVE-2025-21042 in Samsung Android's image processing library. The spyware was embedded in malicious DNG files.

  • web:www.pcmag.com

    A cybersecurity vendor uncovers more details about how a spyware attack exploited a serious flaw in Samsung's software for months to target select users.

  • web:www.pcrisk.com

    What kind of malware is Landfall ? Landfall is Android spyware targeting Samsung Galaxy devices (mainly in the Middle East). It is capable of recording audio, tracking location, and accessing photos, contacts, and call logs. The malware spreads via malicious DNG image files by exploiting a vulnerability in Samsung's image processing library.

  • web:www.rescana.com

    A sophisticated Android spyware campaign leveraging the newly discovered LANDFALL malware has been identified targeting users of Samsung Galaxy devices. This campaign exploits a critical zero-day vulnerability, CVE-2025-21042, in the Samsung image processing library, libimagecodec.quram.so, enabling remote code execution via malicious DNG (Digital Negative) image files. The attack vector is ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.