Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military Personnel
Iran Exploits SS7 Cellular Interconnect Infrastructure to (TL-2026-2609) is a high-severity tracked intrusion set, first published 2026-09-21. It is attributed to Iran (Iran) with medium confidence, affects Global Telecom Industry SS7 / Diameter signalling interconnect (3G/4G, maps to 11 MITRE ATT&CK techniques (T1036, T1095, T1199), and is covered by 9 detection rules and 7 indicators of compromise.
Key facts for TL-2026-2609
- Threat ID
- TL-2026-2609
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-09-21
- Last reviewed
- 2026-09-21
- Attribution
- Iran
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- defense, government administration, telecoms
- Target regions
- Middle East, North America
- Detection rules
- 9
- Indicators of compromise
- 7
Citizen Lab, the Financial Times, and the research initiative Mobile Surveillance Monitor report that Iran exploited long-standing SS7/Diameter telecom-interconnect weaknesses, combined with commercially purchased mobile-advertising location data, to track US military personnel and contractors roaming on regional carriers in Iraq, Bahrain, and other Gulf states before and during the 2026 Iran war. The Pentagon has since confirmed receiving multiple threat reports of the activity and, per Congressional oversight letters, disabled advertising identifiers on government devices, though as of September 2026 lawmakers say the underlying exposure remains only partially addressed.
How Iran Exploits SS7 Cellular Interconnect Infrastructure to works
Between the build-up to the February 2026 US/Israel strikes on Iran and the collapse of the April ceasefire in July 2026, security researchers documented a surge in SS7 (Signaling System No. 7) location-request traffic across Middle East telecom networks aimed at roaming devices belonging to US military personnel and contractors stationed in Iraq, Bahrain, and other Gulf countries. SS7, the decades-old inter-carrier signalling protocol still used to route calls and SMS globally, was designed on a model of implicit trust between operators and lacks robust source authentication or encryption, allowing any party with signalling access to query a subscriber's approximate location by number alone.
Citizen Lab Senior Fellow Gary Miller — who also leads the nonprofit research initiative Mobile Surveillance Monitor — found that rather than attacking military communications systems directly, the campaign abused commercial roaming infrastructure that regional carriers use to service visiting subscribers. Iran reportedly supplemented SS7 queries with commercially purchased advertising data: smartphones broadcast unique mobile advertising identifiers (MAID/AAID/IDFA) into real-time-bidding (RTB) ad-exchange auctions whenever an app serves a targeted ad, and these identifiers — sold onward by data brokers with no buyer vetting — can be correlated into a historical location trail for a device with no compromise of the device itself.
This reporting builds on Citizen Lab's broader April 2026 'Bad Connection' investigation, which separately catalogued how commercial surveillance vendors (CSVs) and 'ghost' front companies posing as legitimate mobile network operators lease Global Title (GT) signalling identifiers from real carriers to inject SS7 and Diameter (the 4G/LTE-era signalling protocol) tracking queries, in some cases pivoting between the two protocols via a device's 'combined attach' 3G/4G registration to bypass Diameter-only firewalls — establishing the general SS7/Diameter tradecraft that outlets subsequently described as being used against US forces, without Citizen Lab confirming the same named vendors executed the Iran-specific campaign.
US officials acknowledged the threat while disputing its operational significance: USCENTCOM told Congress on 2026-04-14 that it had 'received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater,' and a DoD official separately told the Financial Times that claims the tracking meaningfully influenced strike targeting were 'a departure from the facts.' Bipartisan lawmakers (Sens. Wyden and Heinrich, Rep. Harrigan, and others) wrote to DoD CIO Kirsten Davies on 2026-05-28 — the first DoD confirmation that adversaries were using commercial location data against US personnel in an active war zone — calling for advertising IDs to be disabled DoD-wide, privacy-protective browsers to replace default browsers on government devices, and enrollment of servicemembers in data-broker opt-out programs. Military branches subsequently disabled advertising identifiers on government-issued devices (the Army since roughly February 2026, other branches by mid-2026), but a follow-up Congressional letter in September 2026 requesting a DoD Inspector General investigation found troops remained trackable, attributing the gap to late rollout of the mitigations, ad-ID disabling alone being insufficient against non-ad-tech SS7 querying, and continued exposure via personal devices.
No CVE applies: this is an architectural weakness in globally deployed signalling protocols and in the advertising-technology supply chain, not a flaw in a single vendor's product.
MITRE ATT&CK techniques used in TL-2026-2609
Stealth
Command and Control
T1095 Non-Application Layer Protocol
Initial Access
Collection
Discovery
T1430.002 Impersonate SS7 Nodes
Resource Development
T1583 Acquire Infrastructure; T1650 Acquire Access
Reconnaissance
T1590.006 Network Security Appliances; T1591.001 Determine Physical Locations
defense-impairment
T1599 Network Boundary Bridging
collection
Affected products and versions in Iran Exploits SS7 Cellular Interconnect Infrastructure to
- Global Telecom Industry — SS7 / Diameter signalling interconnect (3G/4G roaming infrastructure)
Vulnerable versions: SS7 deployments without signalling firewalls; Diameter (4G/LTE core) without TLS/IPsec enforcement
Fixed in: No universal fix exists; risk is reduced only via signalling-firewall deployment, GT-leasing controls, and interconnect monitoring - Mobile Advertising / RTB Ecosystem — Mobile advertising identifiers (MAID/AAID/IDFA) exposed via real-time-bidding ad exchanges
Vulnerable versions: Devices with advertising ID enabled and location-permissioned ad SDKs installed
Fixed in: Advertising ID disabled at the OS level; ad-supported apps with location permission removed
Remediation for Iran Exploits SS7 Cellular Interconnect Infrastructure to
Immediate actions
- Disable mobile advertising identifiers (MAID/AAID/IDFA) on government-issued and BYOD/personal devices used in theater
- Enroll servicemembers in commercial data-broker opt-out programs
- Replace default mobile browsers on DoD devices with privacy-protective browsers implementing ad blocking and Global Privacy Control
Workarounds
- Operational-security restrictions on personal smartphone use near sensitive installations while deployed
- Prefer host-nation or DoD-managed connectivity over commercial roaming where mission-feasible
Longer-term hardening
- Deploy cross-protocol SS7 and Diameter signalling firewalls that jointly filter 3G and 4G traffic to close the 'combined attach' downgrade gap
- Enforce GSMA IR.21-aligned interconnect routing verification and Diameter Origin-Host/Origin-Realm validation at carriers serving deployed personnel
- Restrict and audit third-party Global Title leasing arrangements with commercial signalling-access resellers
- Complete the DoD Inspector General audit of location-data safeguards across service branches requested by Congress in September 2026
Weaknesses (CWE) in Iran Exploits SS7 Cellular Interconnect Infrastructure to
CWE-306, CWE-311
Timeline of Iran Exploits SS7 Cellular Interconnect Infrastructure to
- Mobile security researchers John Hering and Karsten Nohl publicly demonstrated live SS7-based smartphone location tracking on '60 Minutes' in 2016, establishing SS7 exploitation as a known, unaddressed telecom-industry risk roughly a decade before the Iran campaign was reported.
- Israel and the United States began a series of strikes against Iran, opening the 2026 Iran war during which the SS7 location-request surge against US personnel was later documented.
- US Central Command told Congress it had 'received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater.'
- Citizen Lab published 'Bad Connection,' documenting two long-running SS7/Diameter commercial-surveillance-vendor tracking campaigns and linking roughly 15,700 tracking attempts to shell carriers and vendors including Cognyte and Fink Telecom Services — establishing the cross-protocol SS7/Diameter tradecraft later associated with the Iran reporting, though not confirming the same vendors executed the Iran-specific campaign.
- Senators Wyden and Heinrich and Rep. Harrigan sent a bipartisan letter to DoD CIO Kirsten Davies containing the first DoD confirmation that adversaries were using commercial location data to target US military personnel in an active war zone, calling for advertising-ID and privacy-browser safeguards.
- CENTCOM gained the technical capability to disable commercial location-data sharing on deployed personnel's devices, according to subsequent Congressional reporting.
- The April 2026 US/Israel-Iran ceasefire collapsed after renewed attacks by both sides, coinciding with continued reporting on the telecom-tracking campaign against US forces.
- The Financial Times, via TechCrunch's coverage, reported that Iran had exploited SS7 mobile-network vulnerabilities and commercial ad-tech data to locate US military personnel and contractors in Iraq, Bahrain, and other Gulf states before and during the conflict.
- Citizen Lab published 'US Military Smartphones Targeted Through Roaming and Ad Tech,' detailing the SS7 and mobile-advertising-identifier tracking vectors used against deployed US personnel.
- Citizen Lab published 'How Iran Uses Cellular Infrastructure to Target US Military Phones,' with Senior Fellow Gary Miller stating the persistence of SS7 abuse reflects 'a significant security problem within the mobile operator industry.'
- Senators Wyden and Harrigan requested a DoD Inspector General investigation after finding US troops remained trackable via purchased location data despite the advertising-ID mitigations rolled out earlier in the year.
Sources cited for Iran Exploits SS7 Cellular Interconnect Infrastructure to
- How Iran Uses Cellular Infrastructure to Target US Military Phones
- US Military Smartphones Targeted Through Roaming and Ad Tech
- Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors
- Iran abused mobile networks' vulnerabilities to locate U.S. military in the Middle East, report says
- Surveillance vendors caught abusing access to telcos to track people's phone locations, researchers say
- Iran Exploited Telecom Flaws to Track US Military Personnel, Researchers Say
- Iran used ad tracking to hunt American soldiers: Report
- Troops' phones gave away location data to foreign adversaries
- US troops can still be tracked by purchased location data, and Congress wants to know why
- In letter to DoD, Heinrich Reveals That Foreign Adversaries Are Using Commercial Location Data to Target U.S. Servicemembers in the Middle East
- Commercial location data is being used to target US servicemembers, lawmakers warn
More in threat intel
- Google Gemini AI Model Autonomously Breached Three Real Companies During Authorized Security Evaluation
- LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)
- France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months
- FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Action
- Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operators
Detection coverage for TL-2026-2609
As of 2026-09-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2609 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.