CL-UNK-1054 is an unattributed spyware operator tracked for exploiting the Samsung Galaxy zero-day vulnerability CVE-2025-21042 to deploy the Android surveillance implant LANDFALL in targeted attacks. The activity has been associated with victims in the Middle East and North Africa, with potential targeting identified in Iraq, Iran, Turkey, and Morocco. The operator has been linked to attacks against Samsung Galaxy devices through malicious Digital Negative image files delivered via WhatsApp, with reporting indicating the exploit chain may have functioned as a zero-click infection path. LANDFALL is a full-featured mobile spyware platform used for covert surveillance and data theft. Reported capabilities include collection of microphone audio, location data, photos, contacts, SMS messages, files, and call logs, followed by beaconing to command-and-control infrastructure over HTTPS to retrieve additional payloads. The exploit chain reportedly used crafted image files containing appended archive content to extract shared libraries, execute the spyware, and weaken SELinux policy enforcement to obtain elevated permissions and maintain persistence on compromised devices. The actor demonstrates advanced mobile exploitation and post-compromise tradecraft, including initial access through a zero-day, privilege escalation through security policy manipulation, persistence, and exfiltration. Attribution remains unresolved. Infrastructure and domain-registration patterns have been assessed as resembling Stealth Falcon, also known as FruityArmor, but no direct overlap has been established. Reporting also noted development cues loosely resembling commercial surveillance vendors such as NSO Group, Variston, or Cytrox, but these links are not conclusive and do not support firm attribution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unattributed activity cluster exploiting Samsung Galaxy zero-day CVE-2025-21042 via malicious WhatsApp-delivered DNG images (likely zero-click) to install the LANDFALL Android spyware for broad device surveillance and data theft, with C2 over HTTPS and SELinux policy manipulation for elevated permissions/persistence.
Unattributed activity cluster delivering the Landfall Android spyware to Samsung Galaxy users by exploiting Samsung image library zero-day CVE-2025-21042 via specially crafted DNG images sent over WhatsApp (potentially zero-click), enabling device surveillance and data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.