TechCrunch News 11月07日 19:52
新发现的安卓间谍软件针对三星Galaxy手机
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

安全研究人员发现一款名为“Landfall”的安卓间谍软件,在近一年的攻击活动中,专门针对三星Galaxy手机。该间谍软件利用了一个三星当时未知的零日漏洞,通过发送恶意图片即可在无需用户交互的情况下感染设备。尽管三星已于2025年4月修复了这一漏洞,但此次攻击活动的具体细节此前未被披露。研究人员推测攻击主要针对中东地区个人,并可能与名为Stealth Falcon的已知监控软件供应商存在关联,但尚无法明确归因。Landfall间谍软件具备广泛的设备监控能力,包括访问数据、窃听麦克风和追踪位置,且其代码显示目标机型包括Galaxy S22、S23、S24及部分Z系列。

🕵️‍♀️ **Landfall间谍软件的发现与目标**:安全研究人员发现了名为“Landfall”的安卓间谍软件,该软件在2024年7月首次被检测到,并在近一年的时间内专门针对三星Galaxy手机进行攻击。其攻击活动被描述为“精确攻击”,而非大规模恶意软件传播,暗示其背后可能存在情报搜集的目的。

🛡️ **利用零日漏洞进行攻击**:Landfall间谍软件通过利用三星Galaxy手机软件中一个当时未知的安全漏洞(零日漏洞)进行传播。该漏洞的利用方式是通过发送一张精心构造的图片,很可能通过即时通讯应用传播,并且攻击可能无需受害者进行任何交互即可成功。

🔧 **漏洞修复与潜在关联**:三星已于2025年4月发布补丁修复了该安全漏洞(CVE-2025-21042)。虽然Landfall间谍软件的开发者身份不明,但研究人员发现其共享的数字基础设施与一个名为Stealth Falcon的已知监控供应商有关联,后者曾被发现用于针对阿联酋的记者、活动家和异议人士的间谍软件攻击。然而,这种关联尚不足以明确归咎于特定的政府客户。

📍 **地理目标与功能**:研究人员推测,此类攻击活动主要针对中东地区的个人。Landfall间谍软件具备广泛的设备监控能力,包括访问受害者的照片、消息、联系人、通话记录等数据,还能窃听设备麦克风并追踪精确位置。其代码中明确提到了包括Galaxy S22、S23、S24及部分Z系列在内的多款Galaxy手机作为目标,且受影响的Android版本可能包括13至15。

Security researchers have discovered an Android spyware that targeted Samsung Galaxy phones during a nearly year-long hacking campaign.

Researchers at Palo Alto Networks’ Unit 42 said the spyware, which they call “Landfall,” was first detected in July 2024 and relied on exploiting a security flaw in the Galaxy phone software that was unknown to Samsung at the time, a type of vulnerability known as a zero-day

Unit 42 said the flaw could be abused by sending a maliciously crafted image to a victim’s phone, likely delivered through a messaging app, and that the attacks may not have required any interaction from the victim. 

Samsung patched the security flaw — tracked as CVE-2025-21042 — in April 2025, but details of the spyware campaign abusing the flaw have not been previously reported.

The researchers said it’s not known which surveillance vendor developed the Landfall spyware, nor is it known how many individuals were targeted as part of the campaign. But the researchers said that the attacks likely targeted individuals in the Middle East.

Itay Cohen, a senior principal researcher at Unit 42, told TechCrunch that the hacking campaign consisted of a “precision attack” on specific individuals and not a mass-distributed malware, which indicates that the attacks were likely driven by espionage.

Unit 42 found that the Landfall spyware shares overlapping digital infrastructure used by a known surveillance vendor dubbed Stealth Falcon, which has been previously seen in spyware attacks against Emirati journalists, activists, and dissidents as far back as 2012. But the researchers said that the links with Stealth Falcon, while intriguing, were not enough to clearly attribute the attacks to a particular government customer.

Unit 42 said that the Landfall spyware samples that they discovered had been uploaded to VirusTotal, a malware scanning service, from individuals in Morocco, Iran, Iraq, and Turkey throughout 2024 and early 2025.

Turkey’s national cyber readiness team, known as USOM, flagged one of the IP addresses that the Landfall spyware connected to as malicious, which Unit 42 said supports the theory that individuals in Turkey may have been targeted.

Much like other government spyware, Landfall is capable of broad device surveillance, such as accessing the victim’s data, including photos, messages, contacts and call logs, as well as the tapping of the device’s microphone and tracking their precise location.

Unit 42 found that the spyware’s source code referenced five specific Galaxy phones, including the Galaxy S22, S23, S24, and some Z models, as targets. Cohen said that the vulnerability may have also been present on other Galaxy devices, and affected Android versions 13 through 15. 

Samsung did not respond to a request for comment.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Landfall 三星Galaxy 安卓间谍软件 零日漏洞 网络安全 Stealth Falcon 移动安全 Landfall Samsung Galaxy Android Spyware Zero-Day Vulnerability Cybersecurity Stealth Falcon Mobile Security
相关文章