It has been more than a decade since it was first demonstrated that SS7, the signaling protocol powering mobile networks, suffers from major vulnerabilities that make it possible to track individuals and intercept calls and messages from anywhere in the world.
One might think these vulnerabilities would have been fixed by now, but unfortunately, that is not the case. Mobile networks are still under attack through signaling protocols, mainly by state-sponsored groups and threat actors thriving off the increasing tension in the geopolitical landscape.
Mobile networks become a high-value target in the current geopolitical landscape
The last decade has seen a marked increase in geopolitical risks, driven by strategic competition between the world’s superpowers and increased fragmentation of global trade and security frameworks. We have gone from a world of international cooperation and economic integration to one characterized by escalating conflicts, shifting alliances, economic protectionism, and technological competition.
Today, the Russia-Ukraine war persists, the aftermath of Hamas’s attack on Israel is escalating, and the situation in the South China Sea is intensifying. These rivalries are driving military buildups, economic decoupling, and increased risk of escalation.
In this new, high-tension geopolitical climate, many nation-states with aggressive geopolitical agendas, like Russia or China, look beyond conventional military means to strengthen their positions.
Mobile networks provide desirable targets for adversary nations due to their unique combination of strategic value, technical vulnerabilities, and societal impact. Their role in enabling communication between people and critical services puts them among the most critical of national infrastructure. Attacks on or through mobile networks can be used for espionage, disinformation campaigns, or to disrupt critical services relying on telecommunication infrastructure.
Signaling attacks support espionage
Lately, we have seen mainstream media publish reports about large-scale attacks on mobile networks attributed to state-sponsored groups. For example, Salt Typhoon’s attacks on US service providers in 2024 gained significant attention.
But, often hidden from public sight, surgical attacks are constantly carried out through the signaling systems mobile networks rely on to connect and manage calls, texts, and data connections. Through the signaling protocols, threat actors can intercept calls and messages, track where individuals are, collect information on network design and vulnerabilities for future attacks, or disrupt services through DoS attacks.
The information that can be harvested using signaling attacks is highly relevant to adversaries. Intercepting communication is invaluable in gathering information about government officials, military personnel, journalists, and political dissidents. Even without knowing the content of the communication, details from the signaling alone—such as who is contacting whom—can reveal patterns of relationships and indicate whether noteworthy activity is occurring. Likewise, tracking where these individuals are and where they go can tell intelligence agencies a lot about their activities.
Beyond espionage, we have also seen how mobile networks have played a crucial role in establishing information advantages and supporting military operations in the war in Ukraine. Enea has previously covered various aspects of this in depth, for example, here.
Why are SS7 attacks still possible over 10 years later?
Considering how important it is to protect mobile networks from a national security perspective, and that the vulnerabilities in SS7 have been known for more than 10 years, how can adversary states still exploit them for espionage? Why have we not been able to secure them properly?
On the bright side, a lot has happened with signaling security since 2014. The GSMA has issued recommendations for signaling security, and many mobile network operators (but far from all!) have deployed signaling firewalls to implement them. There are initiatives to improve intelligence sharing (e.g., GSMA’s MoTIF ), and the industry, as well as individual operators, have started to tackle the issues with Global Title leasing (a practice threat actors use to gain access to the signaling network).
The bad news is that this has not been enough. One reason it has not been possible to mitigate the vulnerabilities in SS7 is that it was designed with an assumption of trust: no unauthorized access would be possible, and all communicating parties were well-meaning. Today, access to the signaling network is available for anyone willing to pay for it, including state-sponsored threat actors.
Since this is a foundational design issue, it is not possible to fix with software updates. And because it is globally deployed and deeply embedded into the international roaming infrastructure, it is also not easily retrofitted. The cost and trouble of replacing SS7 for all mobile traffic is too high, so it will continue to be in service for the foreseeable future. And even if it could be replaced entirely by
Diameter and GTP-C, which are used for signaling in 4G networks, are also based on similar trust assumptions. 5G roaming is very much delayed and will not happen for many years, if at all, meaning roaming will still be done with 3G or 4G signaling for the foreseeable future (besides, 5G has other security challenges).
Signaling protocols will continue to be a source of information harvesting and espionage for threat actors and the nation-states behind them. The demand for espionage through mobile networks is strong, fueled by conflicts and war. This must be recognized as a threat against critical national infrastructure.
What is missing to make signaling secure?
So, how can we protect against geopolitically motivated attacks on or through our mobile networks?
The baseline for mobile network operators is to implement GSMA’s signaling security recommendations for SS7, Diameter, and GTP-C. However, SS7 and other signaling protocols prioritize interoperability and flexibility over strict enforcement and security.
While this made sense under the “walled garden” approach for which it was designed, the openness has led to significant vulnerabilities. The threats become even more substantial due to the ingenuity of threat actors who quickly exploit new vulnerabilities, including those emerging with 5G. This makes security much more challenging, as there will always be new attack methods and manipulations that threat actors test.
To counter this evolving threat landscape, mobile network operators must adopt a proactive, intelligence-driven approach to security. Signaling firewalls must protect SS7, Diameter, and GTP-C, while also being ready for 5G to ensure protection across all signaling attack surfaces. However, signaling firewalls alone are not enough to counter state-sponsored threat actors who leverage the signaling protocols' relative openness to find new ways to bypass the filtering.
This is why threat intelligence is needed to enhance detection capabilities. By collecting and analyzing signaling data, operators can understand who the threat actors are and how they try to bypass firewalls. With access to global signaling data, mobile network operators can gain early warnings about emerging threats. This intelligence must be contextualized to make it actionable. It is not enough to understand that a threat exists; it must also be understood how it could affect a specific network and how it can be blocked. Only then can signaling firewalls be enhanced to provide robust protection.
Furthermore, protecting critical national infrastructure is a national interest. Sharing threat intelligence with partners and national security agencies is essential to building a comprehensive signaling defense and national resilience.
Comments