TWO SPYING CAMPAIGNS EXPLOIT TELECOM PROTOCOL FLAWS
AI DESK■ 2 MIN READ
SAT, APR 25, 2026■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
Citizen Lab researchers have identified two separate espionage operations exploiting known vulnerabilities in SS7 and Diameter protocols to track individuals across 2G, 3G, 4G, and 5G networks.
Security researchers at Citizen Lab have documented two distinct spying campaigns that leverage weaknesses in fundamental telecommunications infrastructure to conduct surveillance and location tracking.
The attacks target SS7 and Diameter protocols—core systems that underpin global mobile networks. SS7 has been exploited for years by both state actors and criminal groups, while Diameter vulnerabilities represent a newer attack vector affecting 4G and 5G infrastructure.
These protocols handle critical functions including call routing, messaging, and authentication across carriers worldwide. Their weaknesses allow attackers to intercept communications and pinpoint targets' locations without requiring access to devices or carrier cooperation.
The dual campaigns signal that sophisticated threat actors continue to abuse these known flaws despite years of public disclosure. The ability to track individuals across multiple network generations—from older 2G infrastructure to cutting-edge 5G—demonstrates that network security gaps persist across the entire mobile ecosystem.
Telecommunications carriers have struggled to fully patch these vulnerabilities. Widespread remediation requires significant infrastructure upgrades, and many operators have deprioritized fixes due to costs and technical complexity. Legacy systems running 2G and 3G networks remain particularly exposed.
The findings underscore a fundamental challenge in mobile security: the protocols connecting carriers internationally were designed with minimal security considerations decades ago. Retrofitting protections onto this aging infrastructure has proven difficult and incomplete.
Citizen Lab's research joins mounting evidence that location tracking via telecom vulnerabilities represents an ongoing threat to journalists, activists, and other high-value targets. The group previously documented similar campaigns by government-linked actors exploiting these same weaknesses.
Mobile network operators and regulators face pressure to accelerate security upgrades, though the global scope of telecommunications infrastructure makes coordinated improvements difficult to implement.
■ SOURCES
► Techmeme■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE
■ MORE FROM THE SECURITY DESK
Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.
19H AGO— Industry Desk
Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.
19H AGO— Security Desk
Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.
19H AGO— Industry Desk
Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.
19H AGO— Security Desk