Smartphone users trust that a simple picture message is harmless. This story proves otherwise. A new spyware campaign called LANDFALL secretly infected Samsung Galaxy phones through WhatsApp images without the victim tapping, opening, or downloading anything. The attack used a zero-day flaw, stayed hidden for almost a year, and gave hackers full control of targeted devices. This article breaks down what happened, why it matters, and what you should do now to stay safe.
Quick Take: Key Facts at a Glance
- Hackers used a WhatsApp image to install spyware on Samsung phones.
- The exploit abused a zero-day flaw in Samsung’s image codec (CVE-2025-21042).
- No click required. Just receiving the image was enough.
- Targets were mostly Galaxy S22, S23, S24, and Z-series running Android 13–15.
- The issue is patched, but it proves a growing trend: images are the new attack vector.
What Happened: The WhatsApp Image Trap
The campaign began in mid-2024 and focused on Samsung Galaxy phones. Attackers hid malware inside DNG image files that looked like normal WhatsApp photos. The file name format even mimicked WhatsApp’s auto-naming style, such as IMG-20240723-WA0000.jpg.
Once the image hit the phone, Samsung’s own image-processing library opened it automatically in the background. That library had a flaw. It unpacked the hidden spyware without warning the user.
Key facts about the exploit:
- The flaw lived inside libimagecodec.quram.so, a core Samsung file.
- The malicious image carried a ZIP archive fused to the end of the photo.
- The phone unpacked and executed the spyware on its own.
- Hackers gained access to the mic, GPS, photos, contacts, call logs, and messages.
This section shows how something as routine as a shared photo can bypass every “don’t click bad links” habit we’ve learned. The new threat surface is not bad apps. It is basic phone functions we never think about.
The attack succeeded because it weaponized something we all trust: pictures.
Relevant Source (Palo Alto Networks Unit 42): New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Galaxy Phones
Unit 42’s primary research details the LANDFALL campaign, showing how malformed DNG images exploited Samsung’s libimagecodec.quram.so zero-day to deliver full-feature spyware via WhatsApp.
Relevant Source (NIST NVD): CVE-2025-21042 Detail
The official NVD entry confirms the out-of-bounds write vulnerability in Samsung’s image codec prior to the April 2025 SMR, enabling remote code execution when crafted images are processed.
Why This Matters to Normal Users
Most people think hacking requires clicking a shady link or downloading a sketchy app. This attack broke that rule. It required no action from the victim. Just being sent the image was enough to get infected.
That changes the safety landscape in three ways:
- Zero-click hacks are rising. You do not have to do anything wrong to get hacked.
- Image files are no longer “safe by default.” Phones auto-render images, which creates silent entry points.
- Commercial spyware is now plug-and-play. Governments and private buyers can deploy it like a subscription service.
For Samsung owners, the immediate danger is low because patches exist. The bigger point is that phone security habits must evolve. The old advice of “don’t download unknown apps” does not protect you here.
You can be a careful user and still get hacked. That is the new reality.
Relevant Source (CISA): Mobile Communications Best Practice Guidance
This handbook explains practical steps to reduce mobile attack surface and silent exploitation risk, including limiting auto-processing of media and enforcing timely updates.
Relevant Source (Google Project Zero): A deep dive into an NSO zero-click iMessage exploit
Project Zero’s technical analysis shows how image parsing in messaging can enable zero-click compromise, proving users can be infected simply by receiving a crafted message.

From Photo to Backdoor: The Image Exploit Chain
This was not a virus in the normal sense. It was a malformed image designed to break the rules of the phone’s picture viewer.
Think of it like a birthday gift box that looks normal on the outside. When opened, a hidden compartment inside releases something toxic.
The process:
- Attacker sends fake WhatsApp image.
- Samsung’s image library automatically processes it.
- A flaw in the library extracts the hidden ZIP file.
- The ZIP installs a small shared object file (.so).
- That file runs the spyware in the background.
- Hackers gain full surveillance access.
No broken WhatsApp. No malicious app install. Just a flawed image handler that trusted the file too much. The weak point was not WhatsApp. It was Samsung’s internal image decoder.
What You Should Do Now
Even though the vulnerability is patched, this style of attack is not going away. Mobile users should adjust their habits.
Action steps:
- Update your Samsung device immediately
- Turn on automatic security updates
- Avoid long-delayed Android versions (13–15 users were hit hardest)
- Restart your phone weekly (it breaks some persistent malware)
- Disable auto-download of media in messaging apps
- Use Samsung’s “Security and Privacy” dashboard to check permissions
Update now. Assume no file is harmless. If your Samsung phone has not received updates since April or September 2025, go to Settings → Software Update → Download and install right now.
The Bigger Picture: The Spyware Arms Race
LANDFALL is part of a growing industry: private-sector offensive actors (PSOAs). These are commercial spyware developers who sell to governments, not criminals. They operate legally, but their tools often get used for political surveillance.
Trends worth noting:
- Pegasus (iOS) and LANDFALL (Android) used the same playbook.
- Zero-days are treated like weapons, not bugs.
- Phones are replacing computers as the top espionage target.
- The “image exploit” pattern has now hit both Apple and Samsung.
The long-term fix is not user behavior. It is deeper cooperation between researchers and phone vendors. Until then, users need to assume that messaging apps are not neutral ground.
Smartphones are now battlefield devices. Security patches are your armor.
Relevant Source (Google Threat Analysis Group): TAG Bulletin: Q2 2025
Google’s researchers document how state-backed actors and commercial surveillance vendors repeatedly recycle zero-days and exploit delivery methods, illustrating the ongoing spyware arms race across iOS and Android.
Relevant Source (The White House): Joint Statement on Efforts to Counter the Proliferation and Misuse of Commercial Spyware
This multinational policy commitment explains how governments are responding to PSOAs and sets guardrails for spyware use, confirming the broader policy and geopolitical dimensions behind campaigns like LANDFALL and Pegasus.
Final Take: Zero-Click Attacks Demand Action
A single WhatsApp image hijacked Samsung phones for almost a year before anyone noticed. That should reset how we think about mobile safety. The good news is that the fix already exists. The bad news is that the attack method will return in new forms.
Update your phone, tighten your message settings, and stay alert. If zero-click attacks are the future, passive users will be the first victims.
FAQ
Was WhatsApp hacked?
No. The flaw was in Samsung’s image-processing library, not WhatsApp.
Which Samsung models were affected?
Primarily Galaxy S22, S23, S24, and Z-series on Android 13–15.
Can this still infect my phone today?
Not if your device has the April or September 2025 security patches installed.
Do iPhones have similar risks?
Yes. Apple faced similar image-based attacks in 2025.
Can antivirus apps stop this? Usually not. Zero-click exploits bypass normal detection.
How JENI Helps You Stay One Step Ahead
Digital threats are now silent, invisible, and built to bypass normal user behavior. Most people only think about security when something goes wrong, but today’s attacks prove that prevention is the only real defense. JENI was built for users who want performance, stability, and control without subscriptions, ads, or data tracking. While this specific attack targeted phones, the same “silent exploit” pattern is already shifting toward laptops and desktops, which is where JENI steps in.
Why JENI Matters in the New Threat Landscape
- Cleans and repairs core system files that malware often hides inside
- Removes leftover payloads from browser caches, temp folders, and hidden directories
- Gives full user control with no background processes or phone-home tracking
JENI keeps your system lean, predictable, and harder to exploit by removing the clutter and weak points hackers rely on. The cleaner and more stable your machine is, the less room there is for hidden code to live in the shadows. JENI gives you the kind of maintenance most people never do, but absolutely should.
What Makes JENI Different
- One-time purchase. No subscriptions.
- Fully offline capable. No data harvesting, no telemetry.
JENI focuses on the two things most companies ignore: long-term stability and user freedom. Instead of bloated “security suites” that run in the background and slow your machine, JENI only runs when you choose. That means zero hidden CPU drain, zero cloud tracking, and zero forced renewals.
Your phone may be the first target, but your computer is still the biggest one. JENI exists because people deserve tools that fix, protect, and optimize without selling their data or locking them into fees. If you want a faster, cleaner, and safer device, without the noise, JENI is the upgrade that pays for itself the first time something goes wrong.

