
Operation Signal-Trace: New Commercial Surveillance Platform Exploits SS7/Diameter for Global Mobile Tracking
Researchers have identified a sophisticated surveillance campaign leveraging commercial tools to exploit mobile signaling protocols. The attack enables real-time location tracking and SMS interception without victim interaction.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- Citizen Lab
- Read Time:
- 5 min
Executive Summary
Encrygma intelligence analysts have monitored a significant escalation in the deployment of commercial surveillance tools targeting global mobile infrastructure. Building on the "Bad Connection" report released by Citizen Lab, new evidence suggests that a previously unidentified commercial surveillance vendor (CSV) is actively weaponizing vulnerabilities in the SS7 (Signaling System No. 7) and Diameter protocols. Unlike traditional mobile spyware that requires a device-side implant, this campaign operates at the network level, allowing for the silent tracking of high-profile individuals across international borders. The campaign has been observed affecting networks in Cambodia, China, Israel, Italy, and the United Kingdom, highlighting the systemic risk to global telecommunications.
Threat Analysis
The shift toward signaling-level exploitation represents a strategic pivot for mercenary spyware groups. As mobile operating systems like iOS and Android harden their kernels against zero-click exploits, attackers are moving "down the stack" to the telecommunications layer. By exploiting the inherent trust in roaming protocols, these actors can query a subscriber's location, intercept unencrypted SMS messages (including 2FA codes), and redirect calls. This method is particularly dangerous because it leaves no forensic trace on the target's physical device, rendering traditional Mobile Device Management (MDM) and endpoint security solutions ineffective. The ability to track targets without any user interaction makes this one of the most stealthy vectors in the current threat landscape.
Technical Details
The current campaign utilizes a technique known as "GT (Global Title) Spoofing." The attackers gain access to the SS7 network through low-tier mobile operators or leased access points in jurisdictions with lax regulatory oversight. Once connected, they issue MAP (Mobile Application Part) messages, such as anyTimeInterrogation (ATI) or provideSubscriberInfo (PSI), to the target's Home Location Register (HLR). In the Diameter protocol used in 4G and 5G networks, similar queries are made via the S6a interface. Recent observations indicate the use of a sophisticated TCAP (Transaction Capabilities Application Part) layer bypass that allows the attackers to circumvent signaling firewalls by fragmenting malicious queries or masquerading as legitimate billing traffic. This allows the malicious signaling traffic to blend seamlessly with normal roaming activity.
Attribution Assessment
While the technical sophistication mirrors nation-state capabilities, the infrastructure and targeting patterns strongly suggest a commercial surveillance vendor. The activity has been linked to centralized platforms marketed to intelligence agencies and private entities. Similarities in the command-and-control (C2) structure point toward a successor or affiliate of known entities like the NSO Group or Candiru, though the specific toolset appears to be a new iteration of signaling-based systems. The geographic spread of the targets—spanning Europe, Southeast Asia, and the Middle East—indicates a diverse client base rather than a single state-sponsored objective. The financially motivated nature of the exploit brokers involved further confirms the commercial mercenary model.
Implications
The commercialization of signaling-layer attacks democratizes high-end surveillance. Any entity with sufficient capital can now track government officials, journalists, and corporate executives globally. The ability to bypass two-factor authentication (2FA) via SMS interception poses a direct threat to corporate account security and financial systems. Furthermore, the lack of visibility for mobile operators into cross-border signaling traffic makes this a systemic vulnerability that cannot be patched by a single software update. This creates a persistent threat to privacy and security that bypasses the traditional security boundaries of the mobile device itself.
Recommendations
Encrygma recommends that high-risk individuals transition all sensitive communications to end-to-end encrypted (E2EE) platforms that do not rely on SMS for identity verification. Organizations should implement hardware-based security keys (e.g., FIDO2) to mitigate the risk of 2FA interception. On a structural level, mobile network operators must deploy advanced Signaling Firewalls capable of stateful inspection of MAP and Diameter traffic. Furthermore, organizations should conduct regular audits of mobile fleet security and encourage the use of eSIMs with enhanced security profiles to mitigate the impact of signaling-based tracking.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Apple Expands Global Mercenary Spyware Alerts to 110 Countries Amid Escalating Surveillance Threats

Escalating Pegasus Deployments: New Zero-Click Campaigns Target Civil Society in Serbia

