Iran-Linked Actors Track US Military Personnel via SS7 Roaming Abuse and Ad-Tech Location Data
Iran-Linked Actors Track US Military Personnel via SS7 (TL-2026-1458) is a high-severity advanced persistent threat campaign, first published 2026-07-17. It is linked to a Iran-nexus actor with medium confidence, affects Multiple Regional Mobile Network Operators SS7 (Signaling System 7), maps to 17 MITRE ATT&CK techniques (T1020, T1036, T1046), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-1458
- Threat ID
- TL-2026-1458
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-07-17
- Last reviewed
- 2026-07-17
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- government administration, military, defense-contractors
- Target regions
- Middle East, Gulf, bahrain, iraq, Iraqi Kurdistan
- Detection rules
- 9
- Indicators of compromise
- 16
US military personnel and contractors deployed across the Gulf were tracked before and during the Iran war through two parallel surveillance vectors: abuse of SS7 roaming-location queries against Middle Eastern telecom networks, and Iran-linked exploitation of commercial advertising/real-time-bidding (RTB) location data to geolocate phones in Iraqi Kurdistan. The campaign was documented by the Mobile Surveillance Monitor research initiative and reported by the Financial Times, with Citizen Lab Senior Research Fellow Gary Miller attributing at least some SS7 tracking attempts to an Iranian mobile network operator.
How Iran-Linked Actors Track US Military Personnel via SS7 works
In the run-up to, and during, the US-Israeli military campaign against Iran in late February 2026 and Tehran's subsequent missile and drone retaliation against US forces in the Gulf, telecom networks across the Middle East recorded a sustained surge of SS7 (Signaling System 7) location-request traffic — commonly called 'SS7 pings' — targeting the phones of US military personnel and contractors roaming on regional carriers. SS7 is a decades-old inter-carrier signaling protocol still used globally to route calls and SMS between operators; it contains long-documented design weaknesses that let any party with legitimate (or abused) network signaling access query a subscriber's approximate real-time location by interrogating home-location-register (HLR) and visitor-location-register (VLR) records for a roaming device, without compromising the device itself.
Telecom data reviewed by the Financial Times and shared by the nonprofit Mobile Surveillance Monitor research project — founded by Citizen Lab Senior Research Fellow Gary Miller — showed regional carriers repeatedly fielding and, in some cases, blocking these location-request bursts against specific roaming subscribers. Analysis of the blocked requests produced a signaling 'fingerprint' that Miller linked to an Iranian mobile network operator, matching several other tracking attempts in the dataset. Miller characterized the pattern as 'very specific user targeting,' noting the actors were 'targeting specific devices' rather than conducting broad surveillance, and assessed that 'Iran absolutely has capabilities to get real-time, immediate, and continuous location information,' whether via SS7 abuse or other mobile network access in the region. Targeting concentrated on US personnel and contractors in Bahrain and Iraq, where tens of thousands of American troops are stationed, rather than against military communications systems directly — the campaign instead abused ordinary commercial roaming infrastructure that services any traveling subscriber's device.
A second, distinct tracking vector ran in parallel: a US official told the Financial Times that Iran-linked actors separately abused commercially available advertising/ad-tech location databases — the kind of granular device-location data harvested and brokered through mobile advertising SDKs and real-time-bidding (RTB) auction pipelines — to track phones belonging to US personnel specifically in Iraq's semi-autonomous Kurdistan region. This vector requires no telecom-level access at all; it exploits the ordinary advertising-identifier/location data-broker supply chain that most mobile apps feed by default, illustrating how commercial ad-tech has become a parallel, lower-barrier surveillance channel usable by state actors without any protocol exploitation.
US Central Command acknowledged receiving reports of the tracking activity but disclosed minimal detail on protective countermeasures taken; some US officials reportedly downplayed the operational significance of the tracking data to the FT. Researchers characterized the dual-vector campaign — combining a legacy telecom-signaling weakness with commercial ad-tech data supply chains — as reflecting a significant evolution and growing sophistication in Iran's use of both telecom infrastructure and commercial data markets for intelligence collection and, potentially, target identification supporting kinetic operations during an active conflict.
MITRE ATT&CK techniques used in TL-2026-1458
Exfiltration
T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service
Defense Evasion
Discovery
T1046 Network Service Discovery
Command and Control
T1071 Application Layer Protocol; T1102 Web Service
Collection
T1119 Automated Collection; T1213 Data from Information Repositories
collection
T1430.002 Impersonate SS7 Nodes
Network Effects
T1449 Exploit SS7 to Redirect Phone Calls/SMS
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts
Reconnaissance
T1589 Gather Victim Identity Information; T1590 Gather Victim Network Information; T1591 Gather Victim Org Information; T1596 Search Open Technical Databases
Affected products and versions in Iran-Linked Actors Track US Military Personnel via SS7
- Multiple Regional Mobile Network Operators — SS7 (Signaling System 7) inter-carrier roaming signaling infrastructure
Vulnerable versions: SS7 MAP-layer roaming/location-query interfaces (protocol-inherent, all deployments without signaling firewalls)
Fixed in: Networks with deployed SS7/Diameter signaling firewalls filtering unsolicited location-query MAP operations - Mobile Advertising / Ad-Tech Industry — Real-time bidding (RTB) location data broker pipelines and advertising SDK identifiers (AAID/IDFA-class)
Vulnerable versions: Default advertising-identifier and location-sharing configurations on consumer mobile apps
Fixed in: Devices with ad-ID reset/opt-out and location permissions restricted
Remediation for Iran-Linked Actors Track US Military Personnel via SS7
Patches
- No software patch applicable — SS7 is a protocol-level, inter-carrier trust design weakness rather than a discrete vulnerability with a vendor fix
Immediate actions
- Deploy/verify carrier-side SS7 signaling firewalls (e.g., filtering of unsolicited ProvideSubscriberInfo, AnyTimeInterrogation, and SendRoutingInfo-class MAP queries) on all roaming-partner interconnects
- For deployed personnel, disable or restrict mobile advertising identifier (AAID/IDFA) sharing and limit background app location permissions on government and personal devices
- Issue OPSEC guidance restricting personal-device roaming on host-nation commercial networks in theater; prefer managed/military communications where mission-critical
- Coordinate with host-nation and roaming-partner carriers to flag and block signaling traffic fingerprinted to the implicated Iranian operator
Workarounds
- Use of managed devices with location-permission lockdown and ad-ID reset/opt-out
- Airplane-mode / SIM-out discipline for sensitive movements in theater
- Preference for carriers/networks known to operate signaling firewalls
Longer-term hardening
- Expand telecom threat-intel sharing (e.g., via GSMA FASG / Mobile Surveillance Monitor-style initiatives) to fingerprint and block repeat-offender operators abusing roaming trust relationships
- Push carriers toward Diameter/5G signaling security controls and SS7-to-Diameter interworking firewalls to close legacy protocol gaps as networks migrate
- Engage the mobile advertising/RTB industry on tightening geolocation data-broker access controls and contractual restrictions against military-adjacent target lists
- Institutionalize pattern-of-life/OPSEC training on ad-tech location leakage for deployed and contractor personnel
Timeline of Iran-Linked Actors Track US Military Personnel via SS7
- Telecom data later reviewed by the Financial Times shows regional Middle East carriers beginning to field a surge of SS7 location-request ('SS7 ping') traffic against roaming subscriber devices tied to US military personnel, in the run-up to the US-Israeli campaign against Iran.
- Mobile Surveillance Monitor telemetry shows the SS7 location-request surge was not confined to Bahrain and Iraq alone but affected telecom networks across several Middle Eastern countries in the run-up to the conflict, per Security Boulevard's review of the underlying research.
- US-Israeli military assault on Iran begins (late February 2026); SS7 location-request activity against US personnel roaming in the Gulf continues through this period per Mobile Surveillance Monitor data.
- Iran retaliates with missile and drone strikes against US forces and military installations across the Gulf region; SS7 tracking-request bursts and ad-tech-based location tracking in Iraqi Kurdistan continue into the early days of the conflict.
- Financial Times publishes the first public report on the SS7 roaming-abuse and ad-tech location-tracking campaign, citing telecom data reviewed from the Mobile Surveillance Monitor research project and unnamed US officials.
- Multiple outlets (The Defense Post, SOFX, IBTimes, TechNadu, Türkiye Today, DiyaTV, Sahara Reporters) republish and expand on the FT reporting, adding detail on Bahrain/Iraq targeting and CENTCOM's acknowledgment of the reports.
- Per Security Boulevard's follow-up reporting, unnamed US officials publicly dispute suggestions that the mobile tracking data played a significant role in enabling Iranian kinetic strikes against US forces, contesting the operational-impact framing of the FT's original report.
- Security Boulevard and other outlets publish additional analyst commentary characterizing the campaign as a significant evolution in Iran's telecom-based intelligence-collection sophistication, describing it as 'a coordinated campaign' combining SS7 abuse with commercial advertising-identifier tracking.
- Citizen Lab publishes Senior Research Fellow Gary Miller's analysis and on-record attribution, linking at least some blocked SS7 tracking attempts to a fingerprint matching an Iranian mobile network operator.
Sources cited for Iran-Linked Actors Track US Military Personnel via SS7
- US military smartphones targeted through roaming and ad tech
- Financial Times: US military smartphones targeted through roaming and ad tech (Congressman Pat Harrigan media reprint)
- US Troops Tracked Through Mobile Phones During Iran Conflict: Report
- Middle Eastern Telecom Networks Targeted in Cyber Campaign to Track US Personnel During War: FT
- Iran used roaming systems, ad tech to track US troops in Gulf: Report
- Iran Hacked Middle-East Mobile Networks To Track US Personnel During War — Report
- Iran Tracked US Troops Using Cellular Flaws and Ad Brokers
- Iran Used Mobile Phone Tracking to Hunt US Troops Before Strikes During War
- US personnel faced phone-tracking campaign during Iran war – FT
- Iran Reportedly Abused SS7 Mobile Network Flaws to Locate US Military
- Iran Exploited Telecom Flaws to Track US Military Personnel, Researchers Say
- Report: Iran-linked actors exploited mobile networks, ad tech to track US personnel during Gulf conflict
- How Surveillance Companies track you using SS7 on Mobile Networks
More in apt
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)
Detection coverage for TL-2026-1458
As of 2026-07-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1458 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.