Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Surveillance campaigns use commercial surveillance tools to exploit long-known telecom vulnerabilities  – CyberScoop
AttackFeed by Joe Wagner | Surveillance campaigns use commercial surveillance tools to exploit long-known telecom vulnerabilities  - CyberScoop

Surveillance campaigns use commercial surveillance tools to exploit long-known telecom vulnerabilities  – CyberScoop

Posted on April 23, 2026 By Tim Starks No Comments on Surveillance campaigns use commercial surveillance tools to exploit long-known telecom vulnerabilities  – CyberScoop
Attack Feeds

Campaigns employing commercial surveillance vendors tracked targets by exploiting mobile phone network vulnerabilities in what researchers said Thursday was the first-ever linking of “real-world attack traffic to mobile operator signalling infrastructure.”

The two unknown parties behind the campaigns mimicked the identities of mobile phone operators with customized surveillance tools, and manipulated signaling protocols and steered traffic through network pathways to hide, according to research from the University of Toronto’s Citizen Lab.

“Our findings highlight a systemic issue at the core of global telecommunications: operator infrastructure designed to enable seamless international connectivity is being leveraged to support covert surveillance operations that are difficult to monitor, attribute, and regulate,” a report published Thursday reads.

“Despite repeated public reporting, this activity continues unabated and without consequence,” Gary Miller and Swantje Lange wrote for Citizen Lab. “The continued use of mobile networks, built on a close inter-operator trust model and relied upon by users worldwide, raises broader questions for national regulators, policymakers, and the telecom industry about accountability, oversight, and global security.”

The attackers relied on identifiers and infrastructure associated with operators around the world, including networks based in Cambodia, China, the self-governing Island of Jersey, Israel, Italy, Lesotho, Liechtenstein, Morocco, Mozambique, Namibia, Poland, Rwanda, Sweden, Switzerland, Thailand, Uganda and the United Kingdom.

They shifted between SS7 and Diameter protocols, the signalling protocols known for 3G and 4G/most of 5G, respectively, according to the report. While Diameter was meant to be more secure than SS7, the Federal Communications Commission in 2024 opened a probe into both its vulnerabilities and SS7’s, and Sen. Ron Wyden, D-Ore., has asked for a Cybersecurity and Information Security Agency report about telecommunications vulnerabilities rooted in both protocols.

But identifying the vendors used in the two surveillance campaigns, or who was behind them, was beyond the researchers’ reach.

“The reality is that there are a number of known surveillance vendors and bad actors in this space, but given the opaque nature of telecommunications signalling protocols, those vendors are able to operate without revealing exactly who they really are,” Ron Deibert, director of Citizen Lab, wrote in his newsletter. “Much of the malicious things they are doing blend into the otherwise voluminous flow of billions of normal messages and roaming signals. They are ‘ghost operators’ within the global telecom ecosystem.”

One of the operators mentioned in Citizen Lab’s report, Israel-based 019 Mobile, wrote back that it didn’t recognize the hostnames referenced in the report as 019 Mobile’s network nodes, and couldn’t attribute the signaling activity it represents to 019 Mobile-operated infrastructure.

Another operator, Sure, told TechCrunch that it doesn’t knowingly lease access to signalling to organizations using it to track individuals, and has taken preventative measures to defend against misuse.

Sure, 019 Mobile and a third operator, Tango Networks UK, didn’t respond to requests for comment from CyberScoop. The Citizen Lab report afforded some grace to the operators.

“It is important to note that the operator signalling addresses observed in the attacks do not necessarily imply direct operator involvement,” it states. “In some cases, access to the signalling ecosystem can be obtained through third-party providers, commercial leasing arrangements, or other intermediary services that allow actors to send messages using operator identifiers from legitimate networks.”

The post Surveillance campaigns use commercial surveillance tools to exploit long-known telecom vulnerabilities appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: Dragos: Despite AI use, new malware targeting water plants is ‘hype’  – CyberScoop
Next Post: US, UK agencies warn hackers were hiding on Cisco firewalls long after patches were applied  – CyberScoop ❯

You may also like

AttackFeed by Joe Wagner | Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK  - The Hacker News
Attack Feeds
Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK  – The Hacker News
April 3, 2026
AttackFeed by Joe Wagner | Why Unofficial Download Sources Are Still a Security Risk in 2026  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Why Unofficial Download Sources Are Still a Security Risk in 2026  – Hackread – Cybersecurity News, Data Breaches, AI and More
April 28, 2026
AttackFeed by Joe Wagner | NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions  - The Hacker News
Attack Feeds
NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions  – The Hacker News
April 17, 2026
AttackFeed by Joe Wagner | Surveillance campaigns use commercial surveillance tools to exploit long-known telecom vulnerabilities  - CyberScoop
Attack Feeds
North Korean Hacker Lands Remote IT Job, Caught After VPN Slip  – Hackread – Cybersecurity News, Data Breaches, AI and More
March 23, 2026

Leave a Reply Cancel reply

You must be logged in to post a comment.

  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.