Citizen Lab Investigation Reveals Telecom Surveillance Exploiting Mobile Networks for Covert Tracking
By
miohtama
A baker's-dozen of insight crammed into one ring.
Summary
The Citizen Lab investigation uncovers two sophisticated telecom surveillance campaigns that exploit global mobile operator signalling infrastructure (3G/4G networks) to conduct covert location tracking and device exploitation. The actors used multi-vector techniques including malicious SMS with hidden SIM card commands to extract location data, spoofed operator identities, and manipulated signalling protocols. The report links real-world attack traffic to mobile operator networks for the first time, revealing how commercial surveillance vendors (CSVs) exploit the telecom interconnect ecosystem for persistent, undetected tracking operations.
Key quotes
· 5 pulledWe identified actors using multiple techniques to track targets by combining 3G and 4G signalling network protocols with direct device exploitation via SMS.
One campaign sent a malicious SMS containing hidden SIM card commands to extract location information, attempting to turn the device into a covert tracking beacon.
Both actors used customized surveillance tooling to spoof operator identities, manipulate signalling protocols, and steer traffic through specific interconnect networks.
Our investigation uncovers two sophisticated telecom surveillance campaigns and, for the first time, links real-world attack traffic to mobile operator signalling infrastructure.
The findings expose how suspected commercial surveillance vendors (CSVs) exploit the global telecom interconnect ecosystem, leverage private operator networks, and conduct covert location tracking operations that can persist undetected for years.
You might also wanna read
Pentagon Confirms Adversaries Using Commercial Phone Location Data to Target US Troops
The Pentagon was warned for nearly a decade that commercial location data from mobile phones could be exploited by adversaries to track US m
Pentagon Confirms Adversaries Using Commercial Phone Location Data to Target US Troops
The Pentagon was warned for nearly a decade that commercial location data from mobile phones could be exploited by adversaries to track and
