LANDFALL is a commercial-grade Android spyware family identified on Samsung Galaxy devices. It has been associated with exploitation of Samsung image-processing vulnerabilities, including TIFF/DNG parsing flaws, and has also been delivered through a zero-click WhatsApp exploit chain in which a malicious image sent to a target inbox triggered device compromise. Reporting links LANDFALL activity to a private-sector offensive actor or mercenary spyware cluster rather than a traditional publicly tracked state APT name. Observed targeting has focused on high-value individuals and organizations in the Middle East and nearby regions. Reported victim geography includes Iraq, Iran, Turkey, Bahrain, Morocco, and Pakistan. The spyware has been described as part of broader commercial spyware activity used by state-backed actors and cyber-mercenaries to compromise secure messaging users by exploiting device and application vulnerabilities rather than breaking message encryption directly. Operationally, LANDFALL demonstrates initial access via exploit delivery, post-compromise surveillance capability, and data theft or collection consistent with spyware operations. The campaign context indicates use of zero-click exploitation, mobile-device compromise, and stealthy collection against selected targets. Known aliases in the supplied material include landfall_operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PSOA-attributed activity cluster using malicious TIFF files with embedded ELF payloads targeting Android, exploiting Samsung TIFF/DNG parsing vulnerability (CVE-2025-21042).
Operators used LANDFALL spyware to compromise Samsung devices via a combination of a Samsung vulnerability and a zero-click WhatsApp exploit.
LANDFALL is a commercial-grade Android spyware used in exploit chains targeting Samsung devices, leveraging vulnerabilities in DNG file processing. The spyware is capable of exfiltrating data and maintaining command and control over infected devices.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.