Full Report
Senior fellow Gary Miller spoke with Cape Cellular about the exploitation of mobile network vulnerabilities to track US personnel during the Iran war. The post How Iran Uses Cellular Infrastructure to Target US Military Phones appeared first on The Citizen Lab.
Analysis Summary
# Threat Actor: Iran-linked State Actors
## Attribution & Identity
The threat actor is identified as Iranian state-affiliated entities. While specific unit designations (such as APT33 or MuddyWater) are not explicitly named in this summary, the activity is attributed to Iranian national interests and state-controlled cellular infrastructure during periods of military conflict.
## Activity Summary
Based on the provided text, the actor has been exploiting global mobile network vulnerabilities—specifically within the SS7 (Signaling System No. 7) protocol—to conduct espionage. This activity occurred notably during the Iran war to track the physical locations and movements of United States personnel. The actor leverages the global roaming interconnect ecosystem to bypass traditional perimeter defenses of foreign telecommunications providers.
## Tactics, Techniques & Procedures
- **SS7 Signaling Exploitation:** Abuse of the Signaling System No. 7 protocol to intercept communications and track location.
- **Location Tracking:** Leveraging cellular metadata to monitor the real-time movement of mobile devices.
- **Interconnect Abuse:** Exploiting the trust relationship between global mobile operators to send malicious signaling commands.
- **Surveillance-as-a-Service Utilization:** Use of commercial surveillance vendor tools that integrate with telecom infrastructure.
- **Ad Tech Exploitation:** (Inferred from headlines) Utilization of advertising technology (Ad-tech) ecosystems to supplement location data.
## Targeting
- **Sectors:** Military, Telecommunications, Government.
- **Geography:** United States (domestic and deployed personnel), Iran, and global roaming hubs.
- **Victims:** US Military personnel, Department of Defense contractors, and individuals carrying US-registered smartphones in proximity to the conflict zone.
## Tools & Infrastructure
- **SS7/Diameter Gateways:** Manipulation of international roaming gateways to query Home Location Registers (HLR).
- **Commercial Spyware:** Mention of Pegasus (NSO Group) in the broader context of Citizen Lab's report on targeted surveillance.
- **Telecom Interconnects:** Use of the global mobile network backbone as the primary delivery mechanism for tracking commands.
## Implications
The continued success of these attacks 15 years after they were first identified demonstrates a systemic failure in the global mobile operator industry. For the US military, this represents a significant operational security (OPSEC) risk, as personnel can be tracked in real-time regardless of their device's application-level security. This capability allows Iran to monitor troop movements, identify clandestine locations, and potentially target individuals for kinetic or further cyber actions.
## Mitigations
- **Mobile Network Hardening:** Mobile operators must implement SS7/Diameter firewalls to filter suspicious signaling queries from unauthorized or high-risk international gateways.
- **Signaling Monitoring:** Continuous real-time monitoring for "Any Time Interrogation" (ATI) queries or other location-based signaling abuse.
- **Personnel OPSEC:** Implementation of strict policies regarding the use of personal mobile devices in active conflict zones or near sensitive facilities.
- **Encryption:** Use of end-to-end encrypted messaging services (e.g., Signal) to protect content, though this does not mitigate the underlying network-level location tracking.
- **Platform Security:** Regular device auditing by specialized forensic entities (such as Citizen Lab) for signs of commercial spyware injection.