New “LANDFALL” Android Malware Uses Samsung 0-Day Vulnerability Hidden in WhatsApp Images

Cybersecurity researchers have uncovered a sophisticated Android spyware campaign called LANDFALL that exploits a zero-day vulnerability in Samsung Galaxy devices to deliver surveillance tools via malicious images in WhatsApp messages. The campaign demonstrates the widespread use of DNG image processing vulnerabilities across mobile platforms, highlighting targeted intrusion activities mainly in the…

Read More
Threat Research | Weekly Recap [09 Nov 2025]

Cybersecurity Threat Research ‘Weekly’ Recap. Adversaries persist with phishing, credential theft, supply-chain compromises, and AI-enabled threats, targeting individuals, organizations, and critical infrastructure across multiple sectors. The report highlights notable campaigns, new backdoors, ransomware evolutions, vulnerabilities, and the increasing use of AI for malware development, detection evasion, and incident response improvements.
#Tycoon 2FA #Fake DMCA #RaccoonO365 #Booking.com “I Paid Twice” #AdE crypto-tax phishing #Bank of Italy phishing #Remcos #SleepyDuck #Gootloader #LANDFALL #Fantasy Hub #Cephalus #Midnight ransomware #DragonForce #MuddyWater #SesameOp #OpenAI C2 #Balancer #Great Firewall

Read More
Cybersecurity News | Daily Recap [08 Nov 2025]

Daily Recap, Malicious NuGet time bombs threaten industrial systems, while Landfall spyware exploits a Samsung zero-click flaw to target devices across regions. State-backed actors continue to use legacy flaws for espionage and destructive campaigns, with new zero-day fixes and AI-powered malware emerging in the threat landscape. #NuGet #Landfall #Log4j #Sandworm #CavalryWerewolf #QNAP #UPenn #CyberCommand

Read More
Landfall Android Spyware Targeted Samsung Phones via Zero-Day

A new Android spyware called Landfall exploited a zero-day vulnerability in Samsung devices for remote code execution, primarily targeting users in the Middle East and North Africa. The attack involved infected DNG images sent via WhatsApp, allowing spying capabilities such as microphone recording and data theft. #CVE-2025-21042 #Landfall #SamsungGalaxy #StealthFalcon…

Read More
In Other News: Controversial Ransomware Report, Gootloader Returns, More AN0M Arrests

This week’s cybersecurity news highlights governmental efforts to remove Chinese Huawei technology from critical networks and ongoing law enforcement operations targeting criminal organizations through covert messaging apps. The stories also cover new vulnerabilities, industry-specific threats, and incident responses that shape the current cybersecurity landscape. #Huawei #AN0M…

Read More
LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices

Unit 42 uncovered LANDFALL, a previously unknown Android spyware family targeting Samsung Galaxy devices that was delivered via malformed DNG image files exploiting a zero-day in Samsung’s image processing library (CVE-2025-21042) and active in mid-2024 through early 2025. The campaign used embedded shared object payloads and infrastructure consistent with commercial spyware…

Read More
Fantasy Hub: Another Russian Based RAT as M-a-a-S

zLabs discovered “Fantasy Hub,” an Android Remote Access Trojan sold as Malware‑as‑a‑Service with documentation, builder bot, and instructions to create fake Google Play pages to deploy spyware and phishing windows targeting banks. The malware abuses default SMS handler privileges, uses a native dropper and WebRTC for live streaming, and has been observed targeting institutions including Alfa, PSB, Tbank, and Sber. #FantasyHub #Alfa #Sber

Read More
Malicious Android apps on Google Play downloaded 42 million times

This report highlights a significant increase in malicious Android apps on Google Play, with over 40 million downloads and a 67% rise in mobile malware targeting users. Key threats include spyware, banking trojans, and adware, with attackers shifting toward social engineering tactics like phishing, smishing, and SIM-swapping to exploit mobile payments. #Anatsa #SpyNote

Read More
Threat Research | Weekly Recap [09 Nov 2025]

Cybersecurity Threat Research ‘Weekly’ Recap. A wide range of topics cover Tor-based SSH backdoors, supply-chain and dev-tooling compromises, cloud abuse and credential theft, active vulnerabilities and exploits, diverse malware families and ransomware trends, phishing and mobile propagation, botnets and anonymized infrastructure, APTs and regional campaigns, detection frameworks and risk management, and a large leak exposing Great Firewall internals.

Read More