Security News

Cybersecurity news aggregator

⚔️
HIGH Attacks Reddit r/netsec

The Citizen Lab Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors

  • What: Research reveals global telecom exploitation by covert actors
  • Impact: Users may be tracked through telecom networks and SIM cards
Read Full Article →

Contents Key Findings Introduction Methods Background: Continued Broken Trust in Mobile Communications Insecure by Design Telecom Surveillance Actors: A Crowded and Shadowy Marketplace Fingerprinting Telecom Surveillance Actors Gateways to Surveillance STA1: A Persistent Location Tracking Campaign STA2: The SIM as the Spy Conclusion Acknowledgements Key Findings Multi-Vector Surveillance: We identified actors using multiple techniques to track targets by combining 3G and 4G signalling network protocols with direct device exploitation via SMS. SIM Card Exploitation: One campaign sent a malicious SMS containing hidden SIM card commands to extract location information, attempting to turn the device into a covert tracking beacon. Sophisticated and Customized Tooling : Both actors used customized surveillance tooling to spoof operator identities, manipulate signalling protocols, and steer traffic through specific interconnect network paths to evade defenses and mask attribution. Global Network Infrastructure: The attacks leveraged identifiers and infrastructure associated with operators worldwide, including networks based in the UK, Israel, China, Thailand, Sweden, Italy, Liechtenstein, Cambodia, Mozambique, Uganda, Rwanda, Poland, Switzerland, Morocco, Namibia, Lesotho, and the self-governing Island of Jersey, demonstrating extensive global reach. Persistent Campaign Activity: Telemetry shared by mobile signalling security provider Cellusys reveals that operator identifiers were reused over multiple years, forming consistent clusters that enabled long-running surveillance operations. Weak Intercarrier Provider OPSEC: Weak screening of interconnect traffic allowed attackers to route surveillance messages through trusted operator pathways, enabling access to targeted networks. Introduction In recent years, several investigations have exposed vulnerabilities in the mobile telecommunications ecosystem and how government security agencies have exploited them to track targets abroad while roaming. These studies include several Citizen Lab reports , along with work from other researchers . Our work builds on those findings, prompting further research into the structural weaknesses that continue to enable and evolve targeted surveillance. In late 2024, the Citizen Lab launched an investigation into coordinated location-tracking activity following the identification of a series of unusual events in mobile signalling firewall logs and further intelligence provided by Cellusys . What initially appeared to be an isolated incident targeting a single mobile subscriber led to a broader investigation that uncovered campaigns by two distinct CSVs conducting long-term espionage operations by exploiting the global telecommunications ecosystem. The first campaign, observed in November 2024, involved a multi-stage effort to track a high-profile mobile subscriber using multiple 3G and 4G networks. Information provided by the targeted user’s network operator indicated that the mobile number belonged to a well-known company executive, further described as a “VVIP.” This context indicated that the user was a high-value surveillance target. In early 2025, we identified an additional coordinated-tracking event, with the use of a specially formatted SMS message. While technically distinct, both campaigns demonstrated advanced, highly structured, and repeated methods consistent with purpose-built surveillance platforms. Our collaboration with mobile industry partners enabled a broad investigation using metadata from signalling logs, packet captures, routing data, and other telecommunications sources to trace the methods and origins of advanced surveillance activity. This analysis identified 4G infrastructure associated with operator networks based in Israel, the United Kingdom, and the Channel Islands. Notably, in prior public reporting these same countries have been linked to CSVs targeting mobile users. Our findings highlight a systemic issue at the core of global telecommunications: operator infrastructure designed to enable seamless international connectivity is being leveraged to support covert surveillance operations that are difficult to monitor, attribute, and regulate. Despite repeated public reporting, this activity continues unabated and without consequence. The continued use of mobile networks, built on a close inter-operator trust model and relied upon by users worldwide, raises broader questions for national regulators, policymakers, and the telecom industry about accountability, oversight, and global security. Methods This report is based on analysis in collaboration with multiple industry firms including the signalling firewall provider Cellusys , international signalling network provider Telenor Linx , telecom data intelligence provider Roaming Audit , and telecom network security firm P1 Security . We validated our research by correlating signalling data with additional independent data sources, enabling analysis of how m...

Share this article