Tobias Engel & SRLabs Disclose SS7 Location Tracking at 31C3
SRLabs demonstrated at 31C3 that SS7 flaws allow global subscriber location tracking and SMS 2FA interception.
Target TechnologySS7 MAP Any Time Interrogation (ATI), MAP-SRI-for-SM
OSI Network LayerLayer 7 / SS7 MAP Protocol
Threat Actor / AttributionCommercial Surveillance Vendors & APTs
Protocol Standard3GPP TS 29.002 (MAP Specification)
โ๏ธ Deep-Dive Technical Analysis
By sending SS7 MAP-ATI requests to home location registers (HLR), attackers can retrieve target cell ID coordinates globally. MAP-SRI-for-SM requests allow diverting incoming SMS 2FA authorization codes.
โก Vulnerability & Exploit Flow
Exploit Vector:
Unverified MAP-ATI cell location query & MAP-MT-ForwardSM interception.
๐ก๏ธ Recommended Defense & Mitigation Protocol
Operator Hardening Strategy:
Deploy GSMA Category 1, 2, and 3 SS7 Firewalls with velocity checking.
๐จ Security Impact & Geopolitical Consequence
Triggered GSMA FS.11 Signaling Firewall guidelines.
๐ Authoritative Standards & External References
TelcoSec Academy Ecosystem ยท app.telcosec.net
Master 5G Core, SS7 Defense & Subsea Cable Auditing
Ready to turn your historical knowledge into certified hands-on expertise? Register free on TelcoSec Academy (https://app.telcosec.net/) to access interactive lab challenges, earn verified skill badges, and level up your cybersecurity career.
โHands-on SS7 & Diameter Signaling Firewalls
โ5G SA Zero Trust Security Architecture
โSync Read-to-Earn XP directly to your profile
๐ Claim +100 Welcome Bonus XP
๐ Create Free Account on app.telcosec.netโInstant access to free labs ยท No credit card required