Iran Exploits SS7 Roaming Infrastructure and Commercial Ad-Tech to Track US Military Smartphones During Operation Epic Fury
Iran Exploits SS7 Roaming Infrastructure and Commercial (TL-2026-2411), also tracked as Operation Epic Fury targeting chain, is a critical-severity advanced persistent threat campaign, first published 2026-09-09. It is linked to a Iran-nexus actor with high confidence, affects US Department of Defense Government-issued smartphones (iOS/Android), maps to 10 MITRE ATT&CK techniques (T1020, T1048, T1071), and is covered by 9 detection rules and 7 indicators of compromise.
Key facts for TL-2026-2411
- Threat ID
- TL-2026-2411
- Also known as
- Operation Epic Fury targeting chain, MSM-2026-07 SS7 campaign
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-09-09
- Last reviewed
- 2026-09-09
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- government administration, defense, military
- Target regions
- Middle East, iraq, bahrain, kuwait, qatar, saudi arabia, jordan, united arab emirates, oman
- Detection rules
- 9
- Indicators of compromise
- 7
Malware and tooling in Iran Exploits SS7 Roaming Infrastructure and Commercial
Malware and tooling: Mobile Surveillance Monitor (MSM), Telecom signaling plane (SS7/MAP/TCAP over MTP/SCCP)
Iranian state-aligned actors exploited Signaling System 7 (SS7) roaming-protocol weaknesses and commercial advertising-technology (ad-tech) data to obtain real-time, continuous location information on US military personnel and defense contractors deployed to Iraq, Bahrain, and the wider Gulf during Operation Epic Fury (the 2026 US-Iran war). The Mobile Surveillance Monitor (MSM) research project flagged a surge of targeted SS7 location queries bearing a technical fingerprint tied to MTN Irancell — Iran's second-largest mobile operator, majority-controlled by state defense-linked stakeholders — combined with advertising-ID harvesting through the programmatic ad supply chain to identify hotels and bases housing US personnel. CENTCOM confirmed to Congress that adversaries exploited commercial location data to target or surveil US personnel in theater; the campaign coincided with kinetic strikes that killed and injured US service members.
How Iran Exploits SS7 Roaming Infrastructure and Commercial works
From the buildup to Operation Epic Fury (the joint US-Israeli air campaign against Iran that opened February 28, 2026), Middle Eastern telecom operators observed and blocked a surge of SS7 (Signaling System 7) 'pings' — protocol requests, invisible to the targeted user, that reveal the approximate location of phones roaming outside their home networks. The requests, analyzed by the Mobile Surveillance Monitor (MSM) research project founded by Citizen Lab senior research fellow Gary Miller, exhibited a distinct technical fingerprint linking at least some of the tracking to an Iranian mobile operator. A shared fingerprint and MSM's traffic-log analysis point to MTN Irancell: Iran's second-largest mobile network operator, 51% held by a state-linked consortium dominated by Sairan (Iran Electronics Industries, a defense-ministry subsidiary under US/EU sanctions), with its subscriber data centre (Arya Hamrah) reportedly run in practice by the military and intelligence services. SS7, a 1970s-era telecom protocol with no built-in authentication or encryption, allows any interconnect partner holding a valid Global Title to issue MAP/TCAP queries such as SendRoutingInformation (SRI) and ProvideSubscriberInfo (PSI) that return the cell tower a device is attached to — accurate to within a few hundred meters in urban areas — and the same signaling plane can redirect SMS, including one-time passcodes used for two-factor authentication on military email and admin systems.
In parallel, Iran exploited advertising technology and the commercial data-broker economy for the same ends. Programmatic advertising real-time bidding (RTB) traffic broadcasts device advertising identifiers (IDFA on iOS, AAID on Android) together with high-resolution GPS coordinates from millions of apps; commercial data brokers aggregate and resell this data, and both can be purchased or obtained by adversaries. MSM and the Financial Times reported that Iran used ad-tech identifiers to identify hotels housing US government staff and defense contractors in Iraq's Kurdistan region and to track specific devices or device clusters. The DoD has known the advertising ID is enabled and leaking on government-issued phones: NSA and CISA both recommend disabling it, the Pentagon OIG found in a 2024 review that DoD had failed to close the vulnerability, DISA was only testing a disablement capability as of May 2026, and CENTCOM confirmed the advertising ID was still not disabled on government-issued smartphones.
The operational impact was kinetic. During the war's first hours and weeks, Iranian strikes hit at least seven US-linked installations, including Al Udeid Air Base (Qatar), Camp Arifjan (Kuwait), and the US Fifth Fleet headquarters in Bahrain, where a missile strike damaged the Manama Crowne Plaza hotel that housed DoD contractor staff. CENTCOM dispersed personnel to commercial hotels across Iraq, Bahrain, and the Gulf to mitigate risk, and Iranian forces and regional proxies subsequently targeted several of those civilian lodgings. CENTCOM data showed 13 US service members killed and 381 wounded in the first 40 days of the operation, with the cumulative toll climbing to roughly 794 wounded in action by September 2026 across the war and follow-on operations. On April 14, 2026, CENTCOM told Congress it had received 'multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater' and acknowledged it took 'unprecedented force-protection measures.' Investigators have not established a direct causal link between the surveillance campaign and specific missile or drone strikes, and an unnamed US official disputed that the data was 'significant' in targeting — but the tracking of individual devices, the sectoral targeting of hotels holding US contractors, and the observed SS7 and ad-tech activity together constitute the first known instance of a US adversary using commercial location data against American forces in an active war zone, per Senator Ron Wyden.
The threat is a double-pronged targeting apparatus rather than a classic malware campaign: (1) SS7 signaling-plane exploitation operating across the trusted roaming-interconnect relationships between an Iranian operator and Gulf carriers (Batelco Bahrain, Zain, STC, Etisalat, du, Ooredoo, Vodafone Qatar, Omantel), and (2) the legal-but-hostile purchase and harvest of commercial advertising and broker location data. Attribution to Iran is supported by the SS7 technical fingerprint, the state-controlled operator infrastructure and its documented intelligence access, and the wartime motive; CSIS researcher Nikita Shah called the development 'a step up in sophistication' for Iran. Precedent for Iranian SS7 use exists — MOIS-linked Charming Kitten/APT35 (Mint Sandstorm) used SS7/SMS interception and 2FA bypass since at least 2015 — and other Iranian cyber actors such as Handala escalated disruptive operations against the US during the same conflict. Mitigation centers on disabling advertising IDs on in-theater devices, enforcing the 2018 geolocation ban, migrating away from vulnerable SS7 roaming toward modern encrypted signaling (GSMA roaming security guidelines), and regulating data-broker sale of location data linked to government personnel.
MITRE ATT&CK techniques used in TL-2026-2411
Exfiltration
T1020 Automated Exfiltration; T1048 Exfiltration Over Alternative Protocol
Command and Control
T1071 Application Layer Protocol; T1095 Non-Application Layer Protocol
Initial Access
T1078 Valid Accounts; T1199 Trusted Relationship
Collection
Resource Development
T1584 Compromise Infrastructure
Reconnaissance
T1591 Gather Victim Org Information; T1592 Gather Victim Host Information
Affected products and versions in Iran Exploits SS7 Roaming Infrastructure and Commercial
- US Department of Defense — Government-issued smartphones (iOS/Android)
Vulnerable versions: All in-theater handsets with advertising ID enabled; All handsets permitted to roam on civilian networks
Fixed in: None announced as of September 2026 - US DoD personnel (personal devices) — Personally owned smartphones carried into conflict zones
Vulnerable versions: Devices without disabled advertising ID / location services
Fixed in: Guidance proposed in May 2026 congressional letter - GSMA ecosystem — SS7/MAP signaling plane (2G/3G roaming interconnect)
Vulnerable versions: All SS7 flavors lacking MAP-layer authentication and encryption
Fixed in: Modern Roaming Uplink Bearer / Diameter with encryption (GSMA recommendations) - MTN Irancell — Iranian mobile network operator (state-controlled interconnect partner)
Vulnerable versions: Roaming/SS7 interconnects with Gulf carriers Bahrain, Kuwait, Qatar, UAE, Saudi Arabia, Oman
Remediation for Iran Exploits SS7 Roaming Infrastructure and Commercial
Patches
- No vendor CVE exists — the vulnerability is protocol-level (SS7/GSM MAP), requiring signaling-fabric modernization rather than a software patch
Immediate actions
- Disable advertising identifiers (IDFA/AAID) on all DoD-issued and in-theater smartphones
- Enforce the August 2018 DoD directive banning geolocation-sharing apps and devices in operational areas
- Pre-install privacy-hardened browsers with ad blocking and Global Privacy Control (GPC) on department-issued devices
- Route in-theater roaming traffic through SS7/Diameter signaling firewalls at interconnect borders; block anomalous SRI/PSI/ATI queries during surges
- Move personnel currently billeted in commercial hotels to hardened facilities where possible
Workarounds
- Issue in-theater custom-firmware handsets with advertising ID, location services, and background data disabled
- Restrict photo/video geotagging and app installs on personal devices carried into theater
- Use separate operational (non-personal) devices that never connect to civilian roaming networks
- Prohibit posting or uploading of military-facility imagery while in theater
Longer-term hardening
- Phase out SS7-based 2G/3G signaling in favor of modern encrypted roaming signaling per GSMA FS.11 / T.11 roaming security guidelines
- Deploy telecom signaling firewalls (SS7/Diameter edge protection) at every US-operations-area roaming interconnect
- Regulate data brokers: prohibit sale of precise location data linked or linkable to government and military personnel
- Adopt zero-trust device posture management with centralized location-sharing and ad-ID kill switches
- Require dual-carrier roaming diversity and pre-validated interconnect-security certifications for all allied networks hosting US forces
Weaknesses (CWE) in Iran Exploits SS7 Roaming Infrastructure and Commercial
CWE-306, CWE-319
Timeline of Iran Exploits SS7 Roaming Infrastructure and Commercial
- Strava's Global Heat Map inadvertently exposed layouts and jogging routes of US military sites in the Middle East, the first major open-data exposure of deployed personnel activity and a driver of the 2018 geolocation ban
- DoD issues directive banning geolocation-sharing apps and devices in operational areas in response to fitness-app and data-exposure disclosures
- Pentagon Office of Inspector General 2024 review concludes the military failed to secure government-issued mobile devices and close the location-data vulnerability, years after the threat was demonstrated to JSOC in 2016
- Operation Epic Fury opens: joint US-Israeli air strikes against Iran; at least seven US-linked installations hit including Al Udeid Air Base (Qatar), Camp Arifjan (Kuwait), and the US Fifth Fleet headquarters (Bahrain); Mobile Surveillance Monitor observes a surge of SS7 location queries across Middle Eastern networks in the buildup
- Iranian missile strike damages the Crowne Plaza hotel in Manama, Bahrain, housing DoD contractor staff; hotels holding US government staff and contractors across Iraq's Kurdistan region and the Gulf are targeted, consistent with ad-tech-informed targeting of commercial lodging
- Military Times reports CENTCOM data showing 13 US service members killed and 381 wounded after 40 days of Operation Epic Fury
- CENTCOM tells Congress it has received 'multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater' and characterizes its force-protection measures as 'unprecedented'
- Bipartisan coalition of 14 lawmakers led by Sens. Ron Wyden and Martin Heinrich and Rep. Pat Harrigan writes DoD CIO Kirsten Davies, stating the Pentagon 'has not taken basic steps to protect U.S. servicemembers'; CENTCOM confirms advertising IDs remain enabled on government-issued phones and that it only rolled out the ability to administratively disable location sharing on managed smartphones in May 2026
- Military.com reports this is the first time DoD has confirmed adversaries using commercial location data to target US military personnel in an active war zone; cited for targeting missile, drone, and roadside-bomb attacks and for counterintelligence
- Lawfare (Justin Sherman) publishes 'Iran War Shows Adversaries Can Exploit Big Data, Too': CENTCOM threat reports, the data-broker ecosystem, and Chinese firms like MizarVision marketing AI-fused commercial/OSINT tracking of US bases and carrier movements
- TechCrunch and Times of Israel pick up the FT/MSM findings; CSIS researcher Nikita Shah calls the ad-tech-plus-SS7 development 'a step up in sophistication' for Iran
- Financial Times investigation citing Mobile Surveillance Monitor research: Iran exploited SS7 roaming vulnerabilities and ad-tech to locate US forces at bases and hotels in Iraq, Bahrain, and other Gulf states during the buildup and early war, supporting strikes that injured personnel
- Citizen Lab's Gary Miller tells the Financial Times that at least some tracking attempts bear a technical fingerprint linked to an Iranian mobile operator and involve 'very specific user targeting'; Middle Eastern telecoms had blocked a surge of SS7 pings
- Citizen Lab publishes follow-up with Miller: commercial surveillance vendors are abusing the global telecom interconnect ecosystem to track targets, and 'there's a significant security problem within the mobile operator industry'
- Common Defense reports 794 US service members wounded in action across Operation Epic Fury and follow-on overseas operations as strikes resume in Iraq, Bahrain, and Kuwait
Sources cited for Iran Exploits SS7 Roaming Infrastructure and Commercial
- US Military Smartphones Targeted Through Roaming and Ad Tech (Citizen Lab / Financial Times)
- How Iran Uses Cellular Infrastructure to Target US Military Phones (Citizen Lab)
- Financial Times: US military smartphones targeted through roaming and ad tech
- Iran abused mobile networks' vulnerabilities to locate US military in the Middle East, report says
- Boosting cyber skills, Iran apparently tried to track US military personnel via phones
- Iran spied on US troops via mobile networks to track exact location during war
- Middle Eastern telecom networks targeted in cyber campaign to track US personnel during war (FT)
- Commercial location data being used to target US servicemembers, lawmakers warn
- Iran War Shows Adversaries Can Exploit Big Data, Too
- Military targeted for first time in war zones by enemies using location tech
- Pentagon says US military personnel are reportedly being targeted using location data, Pentagon letter shows
- In letter to DoD, Heinrich reveals foreign adversaries are using commercial location data to target US servicemembers in the Middle East
- The targeting chain: how the IRGC exploits MTN Irancell's Gulf telecom connections to guide its missiles
- CENTCOM: Operation Epic Fury
More in apt
- Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated Cyberattacks and Data Theft
- Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi (CaptiveCrunch), and Take Over WhatsApp Accounts Against Ukrainian/European Government and Drone-Supply-Chain Targets
- China-Based AI Companies Conducting Industrial-Scale Knowledge Distillation Campaigns Against U.S. Frontier AI Models
- China-Nexus and India-Nexus Espionage Groups Converge on Pakistani Law Enforcement Digitalization Platforms ("One Target, Two Flags")
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign
Detection coverage for TL-2026-2411
As of 2026-09-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2411 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.