Full Report
Discover how SIM swapping fraud has evolved, how cybercriminals bypass security layers, and the best ways to protect yourself from SIM swap attacks. Learn key prevention tips now.
Analysis Summary
# Tool/Technique: SIM Swapping (SIM Swap Fraud)
## Overview
SIM swapping is a type of account takeover fraud where a cybercriminal deceives a telecommunications provider into deactivating a victim's legitimate SIM card and activating a new one (or an eSIM) under the attacker's control. The primary purpose is to intercept SMS-based two-factor authentication (2FA) codes and one-time passwords (OTPs) to gain unauthorized access to financial accounts, cryptocurrency wallets, and sensitive personal data.
## Technical Details
- **Type**: Technique (Account Takeover / Social Engineering)
- **Platform**: Telecommunications Networks (GSM/LTE/5G), Mobile Devices (iOS/Android)
- **Capabilities**: Interception of SMS/Calls, bypass of 2FA, remote number porting, eSIM conversion.
- **First Seen**: Early 2010s; evolved significantly with the introduction of eSIMs and remote porting apps.
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- **T1566 - Phishing**: Using fake websites to gather credentials or PII.
- **TA0006 - Credential Access**
- **T1539 - Steal Web Session Cookie**: Through phishing kits.
- **T1111 - Two-Factor Authentication Evasion**: Core objective of the swap.
- **TA0005 - Defense Evasion**
- **T1556.006 - Modify Authentication Process: Multi-Factor Authentication**: By redirecting the SMS channel.
## Functionality
### Core Capabilities
- **Number Porting/eSIM Conversion**: Attacker initiates a request to move the victim's service to a new physical SIM or a digital eSIM via the provider's mobile app or support channel.
- **Identity Theft**: Fraudsters use harvested Personal Identifiable Information (PII) to impersonate victims during interactions with telecom customer service.
- **SMS Interception**: Once the swap is complete, all incoming traffic (OTPs, recovery links) is routed to the attacker’s device.
### Advanced Features
- **E-Verification Bypass**: In regions with government-mandated biometric or e-verification, attackers use social engineering to trick victims into "approving" a verification prompt on their own device, which actually authorizes the SIM transfer.
- **Hybrid Attacks**: Combining automated phishing kits with live social engineering calls to increase the success rate of the takeover.
## Indicators of Compromise
- **File Hashes**: N/A (Technique-based)
- **File Names**: N/A
- **Registry Keys**: N/A
- **Network Indicators**:
- Phishing domains mimicking telecom providers (e.g., `telecom-verify[.]com`).
- Phishing domains mimicking government identity portals.
- **Behavioral Indicators**:
- Sudden loss of cellular service ("No Service" or "SOS" only) on the victim's device.
- Unexpected notifications from service providers regarding a "SIM Change" or "eSIM Activation."
- Multiple password reset notifications across unrelated accounts (banking, email, social media).
## Associated Threat Actors
- **Scattered Spider (UNC3944)**: Known for aggressive SIM swapping and social engineering of help desks.
- **Lapsus$**: Historically used SIM swapping to breach corporate environments.
- **Various e-Crime/Financial Fraud Groups**: Specialized in draining bank accounts and crypto wallets.
## Detection Methods
- **Behavioral Detection**: Telecommunication providers monitoring for high-frequency SIM changes associated with specific IMEI patterns.
- **Fraud Intelligence**: Using platforms like Group-IB Fraud Protection to identify anomalous login patterns or device fingerprinting changes following a SIM status update.
- **Cross-Channel Monitoring**: Financial institutions checking for "SIM Age" or "SIM Swap status" via API before sending sensitive OTPs.
## Mitigation Strategies
- **Move away from SMS 2FA**: Transition to hardware security keys (YubiKey) or TOTP apps (Google Authenticator, Microsoft Authenticator).
- **Telecom Hardening**: Set up a "Port Freeze" or "SIM Lock" with the mobile carrier that requires a secondary PIN for any changes.
- **Identity Protection**: Be wary of unsolicited calls or texts asking for identity verification or "approving" prompts.
- **Biometric Security**: Use biometric-backed e-verification platforms where available, ensuring never to authorize requests not initiated by the user.
## Related Tools/Techniques
- **Social Engineering**: The primary driver for convincing help desk agents to perform the swap.
- **Phishing Kits**: Used to harvest the PII needed to pass telecom security questions.
- **Number Porting**: A variant where the number is moved to a completely different carrier.