Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military Personnel

Iran Exploits SS7 Cellular Interconnect Infrastructure to (TL-2026-2609) is a high-severity tracked intrusion set, first published 2026-09-21. It is attributed to Iran (Iran) with medium confidence, affects Global Telecom Industry SS7 / Diameter signalling interconnect (3G/4G, maps to 11 MITRE ATT&CK techniques (T1036, T1095, T1199), and is covered by 9 detection rules and 7 indicators of compromise.

Key facts for TL-2026-2609

Threat ID
TL-2026-2609
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-09-21
Last reviewed
2026-09-21
Attribution
Iran
Attribution confidence
MEDIUM
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
defense, government administration, telecoms
Target regions
Middle East, North America
Detection rules
9
Indicators of compromise
7

Citizen Lab, the Financial Times, and the research initiative Mobile Surveillance Monitor report that Iran exploited long-standing SS7/Diameter telecom-interconnect weaknesses, combined with commercially purchased mobile-advertising location data, to track US military personnel and contractors roaming on regional carriers in Iraq, Bahrain, and other Gulf states before and during the 2026 Iran war. The Pentagon has since confirmed receiving multiple threat reports of the activity and, per Congressional oversight letters, disabled advertising identifiers on government devices, though as of September 2026 lawmakers say the underlying exposure remains only partially addressed.

How Iran Exploits SS7 Cellular Interconnect Infrastructure to works

Between the build-up to the February 2026 US/Israel strikes on Iran and the collapse of the April ceasefire in July 2026, security researchers documented a surge in SS7 (Signaling System No. 7) location-request traffic across Middle East telecom networks aimed at roaming devices belonging to US military personnel and contractors stationed in Iraq, Bahrain, and other Gulf countries. SS7, the decades-old inter-carrier signalling protocol still used to route calls and SMS globally, was designed on a model of implicit trust between operators and lacks robust source authentication or encryption, allowing any party with signalling access to query a subscriber's approximate location by number alone.

Citizen Lab Senior Fellow Gary Miller — who also leads the nonprofit research initiative Mobile Surveillance Monitor — found that rather than attacking military communications systems directly, the campaign abused commercial roaming infrastructure that regional carriers use to service visiting subscribers. Iran reportedly supplemented SS7 queries with commercially purchased advertising data: smartphones broadcast unique mobile advertising identifiers (MAID/AAID/IDFA) into real-time-bidding (RTB) ad-exchange auctions whenever an app serves a targeted ad, and these identifiers — sold onward by data brokers with no buyer vetting — can be correlated into a historical location trail for a device with no compromise of the device itself.

This reporting builds on Citizen Lab's broader April 2026 'Bad Connection' investigation, which separately catalogued how commercial surveillance vendors (CSVs) and 'ghost' front companies posing as legitimate mobile network operators lease Global Title (GT) signalling identifiers from real carriers to inject SS7 and Diameter (the 4G/LTE-era signalling protocol) tracking queries, in some cases pivoting between the two protocols via a device's 'combined attach' 3G/4G registration to bypass Diameter-only firewalls — establishing the general SS7/Diameter tradecraft that outlets subsequently described as being used against US forces, without Citizen Lab confirming the same named vendors executed the Iran-specific campaign.

US officials acknowledged the threat while disputing its operational significance: USCENTCOM told Congress on 2026-04-14 that it had 'received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater,' and a DoD official separately told the Financial Times that claims the tracking meaningfully influenced strike targeting were 'a departure from the facts.' Bipartisan lawmakers (Sens. Wyden and Heinrich, Rep. Harrigan, and others) wrote to DoD CIO Kirsten Davies on 2026-05-28 — the first DoD confirmation that adversaries were using commercial location data against US personnel in an active war zone — calling for advertising IDs to be disabled DoD-wide, privacy-protective browsers to replace default browsers on government devices, and enrollment of servicemembers in data-broker opt-out programs. Military branches subsequently disabled advertising identifiers on government-issued devices (the Army since roughly February 2026, other branches by mid-2026), but a follow-up Congressional letter in September 2026 requesting a DoD Inspector General investigation found troops remained trackable, attributing the gap to late rollout of the mitigations, ad-ID disabling alone being insufficient against non-ad-tech SS7 querying, and continued exposure via personal devices.

No CVE applies: this is an architectural weakness in globally deployed signalling protocols and in the advertising-technology supply chain, not a flaw in a single vendor's product.

MITRE ATT&CK techniques used in TL-2026-2609

Stealth

T1036 Masquerading

Command and Control

T1095 Non-Application Layer Protocol

Initial Access

T1199 Trusted Relationship

Collection

T1430 Location Tracking

Discovery

T1430.002 Impersonate SS7 Nodes

Resource Development

T1583 Acquire Infrastructure; T1650 Acquire Access

Reconnaissance

T1590.006 Network Security Appliances; T1591.001 Determine Physical Locations

defense-impairment

T1599 Network Boundary Bridging

collection

T1638 Adversary-in-the-Middle

Affected products and versions in Iran Exploits SS7 Cellular Interconnect Infrastructure to

  • Global Telecom Industry — SS7 / Diameter signalling interconnect (3G/4G roaming infrastructure)
    Vulnerable versions: SS7 deployments without signalling firewalls; Diameter (4G/LTE core) without TLS/IPsec enforcement
    Fixed in: No universal fix exists; risk is reduced only via signalling-firewall deployment, GT-leasing controls, and interconnect monitoring
  • Mobile Advertising / RTB Ecosystem — Mobile advertising identifiers (MAID/AAID/IDFA) exposed via real-time-bidding ad exchanges
    Vulnerable versions: Devices with advertising ID enabled and location-permissioned ad SDKs installed
    Fixed in: Advertising ID disabled at the OS level; ad-supported apps with location permission removed

Remediation for Iran Exploits SS7 Cellular Interconnect Infrastructure to

Immediate actions

  • Disable mobile advertising identifiers (MAID/AAID/IDFA) on government-issued and BYOD/personal devices used in theater
  • Enroll servicemembers in commercial data-broker opt-out programs
  • Replace default mobile browsers on DoD devices with privacy-protective browsers implementing ad blocking and Global Privacy Control

Workarounds

  • Operational-security restrictions on personal smartphone use near sensitive installations while deployed
  • Prefer host-nation or DoD-managed connectivity over commercial roaming where mission-feasible

Longer-term hardening

  • Deploy cross-protocol SS7 and Diameter signalling firewalls that jointly filter 3G and 4G traffic to close the 'combined attach' downgrade gap
  • Enforce GSMA IR.21-aligned interconnect routing verification and Diameter Origin-Host/Origin-Realm validation at carriers serving deployed personnel
  • Restrict and audit third-party Global Title leasing arrangements with commercial signalling-access resellers
  • Complete the DoD Inspector General audit of location-data safeguards across service branches requested by Congress in September 2026

Weaknesses (CWE) in Iran Exploits SS7 Cellular Interconnect Infrastructure to

CWE-306, CWE-311

Timeline of Iran Exploits SS7 Cellular Interconnect Infrastructure to

  • Mobile security researchers John Hering and Karsten Nohl publicly demonstrated live SS7-based smartphone location tracking on '60 Minutes' in 2016, establishing SS7 exploitation as a known, unaddressed telecom-industry risk roughly a decade before the Iran campaign was reported.
  • Israel and the United States began a series of strikes against Iran, opening the 2026 Iran war during which the SS7 location-request surge against US personnel was later documented.
  • US Central Command told Congress it had 'received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater.'
  • Citizen Lab published 'Bad Connection,' documenting two long-running SS7/Diameter commercial-surveillance-vendor tracking campaigns and linking roughly 15,700 tracking attempts to shell carriers and vendors including Cognyte and Fink Telecom Services — establishing the cross-protocol SS7/Diameter tradecraft later associated with the Iran reporting, though not confirming the same vendors executed the Iran-specific campaign.
  • Senators Wyden and Heinrich and Rep. Harrigan sent a bipartisan letter to DoD CIO Kirsten Davies containing the first DoD confirmation that adversaries were using commercial location data to target US military personnel in an active war zone, calling for advertising-ID and privacy-browser safeguards.
  • CENTCOM gained the technical capability to disable commercial location-data sharing on deployed personnel's devices, according to subsequent Congressional reporting.
  • The April 2026 US/Israel-Iran ceasefire collapsed after renewed attacks by both sides, coinciding with continued reporting on the telecom-tracking campaign against US forces.
  • The Financial Times, via TechCrunch's coverage, reported that Iran had exploited SS7 mobile-network vulnerabilities and commercial ad-tech data to locate US military personnel and contractors in Iraq, Bahrain, and other Gulf states before and during the conflict.
  • Citizen Lab published 'US Military Smartphones Targeted Through Roaming and Ad Tech,' detailing the SS7 and mobile-advertising-identifier tracking vectors used against deployed US personnel.
  • Citizen Lab published 'How Iran Uses Cellular Infrastructure to Target US Military Phones,' with Senior Fellow Gary Miller stating the persistence of SS7 abuse reflects 'a significant security problem within the mobile operator industry.'
  • Senators Wyden and Harrigan requested a DoD Inspector General investigation after finding US troops remained trackable via purchased location data despite the advertising-ID mitigations rolled out earlier in the year.

Sources cited for Iran Exploits SS7 Cellular Interconnect Infrastructure to

More in threat intel

Detection coverage for TL-2026-2609

As of 2026-09-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2609 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats