Listen to this Post
A Hidden Threat Inside the Networks We Trust
Your phone can be sitting quietly in your pocket, showing full signal bars and behaving normally, while sophisticated surveillance activity takes place somewhere far beneath the apps and operating system you can see. The danger does not always begin with malware installed on the device. In some cases, the weakness lies in the telecommunications infrastructure that allows mobile networks around the world to communicate with one another.
A major investigation by the University of Toronto’s Citizen Lab has exposed two sophisticated surveillance campaigns that abused this hidden layer of global communications. The research, published in April 2026 under the title Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors, connects real-world surveillance traffic with mobile-operator signalling infrastructure and shows how suspected commercial surveillance actors can exploit trusted telecom interconnections for covert location tracking.
The Most Disturbing Part Is What Users Cannot See
Unlike a conventional cyberattack, this type of surveillance may leave almost no visible evidence on the targeted phone. There may be no suspicious application, no strange notification, no obvious phishing message and no ransomware-style warning. The activity can occur within signalling systems used by telecommunications companies to manage roaming and network connectivity.
Citizen Lab identified two distinct surveillance campaigns and found evidence that they used combinations of 3G SS7 and 4G Diameter signalling, manipulated network identities, controlled routing paths and, in one campaign, sent specially crafted SMS messages containing hidden SIM commands.
What the Investigation Found
The research began after unusual mobile-signalling activity was detected in late 2024. What initially appeared to be an isolated attempt to track a single subscriber eventually developed into a much broader investigation involving two surveillance actors and years of historical telemetry.
Citizen Lab worked with telecommunications security and intelligence companies including Cellusys, Telenor Linx, Roaming Audit and P1 Security to correlate signalling logs, packet captures, routing information, operator configurations and other data sources.
The resulting picture was deeply concerning: sophisticated surveillance actors were not simply attacking a phone or exploiting an ordinary internet-facing server. They were attempting to operate inside the trusted ecosystem that connects mobile operators across borders.
The Telecom Trust Model Became the Attack Surface
International mobile roaming depends on thousands of operators and service providers exchanging signalling information. This architecture was developed around the assumption that participating networks were legitimate and that trusted relationships could be used to make roaming work efficiently.
That model created an enormous advantage for surveillance operators.
Instead of breaking into a smartphone directly, an attacker with sufficient access to signalling infrastructure can potentially send network-level requests toward a subscriber’s operator and attempt to obtain information about where that device is located.
Citizen Lab describes this fundamental problem as part of the broader structural weakness of global telecommunications: the ecosystem contains legacy protocols and business relationships that were designed around trust rather than modern security principles.
SS7 Remains a Problem Decades After Its Creation
One of the technologies involved is SS7, the signalling system historically associated with 2G and 3G mobile networks.
SS7 was created for a telecommunications environment that was dramatically smaller and more controlled than today’s global mobile ecosystem. Strong authentication and modern integrity protections were not central assumptions of the original design.
Yet SS7 remains important because modern mobile networks did not simply abandon older generations of technology. Roaming, SMS and other services continue to rely on legacy infrastructure, creating an environment in which older and newer signalling systems coexist.
That coexistence matters because attackers can exploit the weakest available layer.
Diameter Did Not Completely Solve the Problem
4G networks introduced Diameter, a newer signalling protocol intended to replace many SS7 functions.
But replacing the protocol did not automatically eliminate the underlying trust problem.
Citizen Lab found surveillance campaigns that combined 3G and 4G signalling techniques. The research emphasizes that although newer generations can provide stronger protections, roaming devices and networks may continue to interact with multiple generations simultaneously.
This creates a complicated security environment where an attacker does not necessarily need to defeat the strongest protection in the entire ecosystem. Finding a weaker route can be enough.
The Rise of the “Ghost Operator”
One of the most striking concepts in the investigation is the idea of a “Ghost Operator.”
The term describes surveillance actors that make their traffic appear to originate from legitimate telecommunications infrastructure. Rather than openly announcing their presence, they can manipulate signalling identifiers, exploit legitimate interconnections or use intermediary providers to make surveillance traffic blend into normal telecom activity.
The result is a digital disguise.
To the receiving network, the traffic may appear to be coming from another legitimate operator. The actual party controlling the surveillance operation can remain hidden behind several layers of infrastructure and commercial relationships.
Operator Identities Can Be Used as Digital Masks
Citizen Lab found instances where signalling identifiers were manipulated in ways that could obscure the actual source of traffic or influence how messages were routed.
This is especially significant because telecommunications networks depend on identifying where signalling traffic comes from and where responses should be sent.
If those identifiers can be manipulated or abused, the identity of the attacker becomes much harder to establish.
The research also found that some operator identifiers were repeatedly associated with suspicious activity over long periods, suggesting that these were not isolated experiments but components of persistent surveillance operations.
The Global Reach Was Extensive
The investigation identified infrastructure and operator identifiers associated with networks in numerous countries and territories, including the United Kingdom, Israel, China, Thailand, Sweden, Italy, Liechtenstein, Cambodia, Mozambique, Uganda, Rwanda, Poland, Switzerland, Morocco, Namibia, Lesotho and Jersey.
That geographic spread does not mean that all of those operators knowingly participated in surveillance.
This distinction is critical.
Citizen Lab explicitly warns that the appearance of an operator identifier in surveillance traffic does not necessarily demonstrate that the operator itself was responsible. Access can potentially be obtained through third-party providers, commercial arrangements or intermediary services.
STA1: A Long-Running Location Tracking Operation
Citizen Lab identified the first campaign as Surveillance Threat Actor 1, or STA1.
The campaign demonstrated a sophisticated understanding of mobile signalling, international roaming infrastructure and network defenses.
In one documented incident on November 25, 2024, multiple signalling messages were directed at a subscriber of a Middle Eastern mobile operator. The targeted subscriber was described by the operator as a high-profile individual.
Over several hours, the actor reportedly rotated between different signalling identities and used multiple operators across several countries while attempting to determine the target’s location.
This is important because it demonstrates how surveillance can be conducted as an operational process rather than a single malicious request.
Attackers Could Rotate Through Multiple Identities
Instead of repeatedly sending requests from a single identifiable source, sophisticated surveillance tooling can attempt to distribute activity across different network identities and routes.
This creates a much harder detection problem.
Security teams looking for one suspicious source may see what appears to be a collection of unrelated telecommunications events. But when those events are correlated by timing, behaviour, routing and technical characteristics, a larger campaign can emerge.
Citizen
Historical Evidence Suggests Persistence
One of the most alarming aspects of the research is the duration of the observed activity.
Citizen
That changes the nature of the threat.
This was not simply a short-lived experiment against one telecommunications network. The evidence indicates that some surveillance infrastructure and techniques remained active across extended periods.
STA2 Took a Different Route
The second campaign, STA2, used another particularly disturbing technique.
Instead of relying exclusively on network-level signalling queries, the campaign combined telecommunications signalling with direct interaction involving the SIM card.
Researchers identified specially formatted binary SMS messages containing commands capable of interacting with SIM functionality.
The phone user did not necessarily need to open the message or interact with it.
The SIM Card Could Become the Sensor
This technique is related to the SIMjacker class of attacks previously documented by security researchers.
Certain SIM cards can contain applications designed to receive and process specialized commands. These functions have legitimate purposes, including operator configuration and mobile services.
But if an attacker can send unauthorized commands through the appropriate signalling pathways, those capabilities can potentially be abused.
Citizen Lab reported that the observed campaign used commands designed to obtain device-location information and return it through silent communications.
The implication is chilling: the SIM card itself can become part of the surveillance mechanism.
No App Installation Was Necessary
Traditional spyware operations often require some form of device compromise.
A malicious application may have to be installed, an exploit may need to compromise the operating system, or the target may have to interact with a malicious link.
The telecom attacks described by Citizen Lab operate differently.
The surveillance can take place through infrastructure that the user normally never sees.
That makes conventional endpoint security considerably less useful as a complete defense. A perfectly updated smartphone can still exist inside a telecommunications ecosystem containing legacy trust relationships and vulnerable signalling pathways.
What Information Can Be Targeted?
The surveillance techniques documented in the research were designed to obtain information related to mobile subscribers and their network presence.
Potentially targeted information can include:
Current device location
Cell and network location information
Subscriber or network status
IMEI-related device information
Radio access technology
Local time-zone information
4G tracking-area information
Cell information
This information may appear relatively ordinary when considered individually.
But location data becomes extremely sensitive when collected repeatedly.
Location Data Can Reveal a
A single cell-location event may provide only a rough indication of where a device is.
Repeated tracking is a different story.
A persistent location history can reveal where someone lives, where they work, which offices they visit, where they travel, whom they repeatedly meet and how their daily routines change.
For high-profile individuals, executives, journalists, activists, diplomats and political figures, that information can become extraordinarily valuable.
The surveillance does not necessarily need to listen to a phone call to reveal sensitive information. Sometimes knowing where the phone goes is enough.
The Commercial Surveillance Industry Adds Another Layer
Citizen Lab does not attribute the campaigns in this report to a specific government or organization.
However, the researchers say the evidence is consistent with a commercially developed telecommunications surveillance platform that could support government intelligence activities.
That distinction matters.
Modern surveillance is not necessarily developed and operated exclusively by government agencies. Private companies can develop sophisticated surveillance technologies and potentially provide them to government clients.
This creates a marketplace where highly specialized capabilities can exist outside traditional intelligence organizations.
Attribution Is Extremely Difficult
The use of legitimate operator identities makes attribution particularly challenging.
If surveillance traffic appears to come from a legitimate network, investigators cannot simply assume that the operator responsible for the identifier launched the attack.
The identifier may have been spoofed.
It may have been obtained through an intermediary.
It may have been associated with a commercial service.
Or the infrastructure could have been compromised or misused without the operator’s knowledge.
Citizen Lab therefore deliberately avoids assigning responsibility for the campaigns to a particular government or organization.
Third-Party Interconnect Providers Are a Critical Weakness
International telecommunications depends heavily on interconnect providers that help networks communicate with each other.
That infrastructure is essential for global roaming.
But it can also become a path through which malicious signalling traffic enters the wider ecosystem.
Citizen Lab found routing patterns suggesting that surveillance traffic could enter through third-party interconnect arrangements and then move toward target networks while appearing to originate from legitimate telecom infrastructure.
The lesson is uncomfortable: security cannot stop at the boundary of an individual mobile operator.
The Problem Is Bigger Than One Vulnerability
It would be easy to describe this as an SS7 vulnerability story.
That would be too simplistic.
The deeper issue is architectural.
The global telecom ecosystem contains thousands of organizations, legacy protocols, roaming agreements, interconnect providers, network identifiers and commercial relationships. Securing one operator does not necessarily secure the entire chain.
An attacker may simply search for another path.
Why This Threat Is Different From Ordinary Cybercrime
Most people understand cybersecurity through familiar threats: phishing, ransomware, malware, password theft and data breaches.
Telecom surveillance belongs to a different category.
There may be no ransom demand.
There may be no malicious file.
There may be no compromised corporate server.
There may not even be an obvious indication that the victim has been targeted.
The attacker is abusing the communications infrastructure itself.
The Security Blind Spot Is the Biggest Problem
Citizen Lab describes telecommunications surveillance as particularly difficult to observe because the activity occurs inside a relatively closed ecosystem involving mobile operators, vendors and interconnect providers.
Corporate security teams normally have visibility into endpoints, servers, identity systems and cloud environments.
They generally do not have visibility into every international signalling transaction associated with a mobile subscriber.
That means the people most capable of detecting these attacks may be telecommunications specialists rather than traditional enterprise security teams.
Telecom Security Needs Better Attribution
One of the biggest lessons from this investigation is that identifying malicious traffic is only part of the problem.
Security teams also need to determine where the traffic actually entered the ecosystem.
That requires cooperation among mobile operators, signalling security providers, interconnect companies and regulators.
Without that cooperation, attackers can exploit the gaps between organizations.
The Mobile Network Is Part of the Cybersecurity Perimeter
For years, cybersecurity discussions have increasingly focused on endpoints and cloud infrastructure.
But a mobile phone is not simply a computer connected to the internet.
It is also a subscriber identity attached to a global telecommunications network.
That network controls essential functions such as registration, roaming, signalling and location-related services.
Protecting the device while ignoring the network surrounding it creates an incomplete security model.
Stronger Controls Are Needed Across the Ecosystem
The findings point toward a need for stronger authentication, tighter interconnect controls, better screening of signalling traffic and more transparency around third-party access.
Operators also need mechanisms capable of identifying abnormal combinations of signalling behaviour rather than relying only on individual suspicious messages.
Long-term telemetry matters because sophisticated campaigns can remain quiet enough to avoid immediate detection.
Regulators Have a Role to Play
The issue cannot be solved entirely by private companies.
Telecommunications infrastructure is critical national infrastructure, and signalling systems cross borders by design.
Regulators therefore have an important role in establishing minimum security standards, auditing interconnect arrangements and ensuring that commercial access to signalling infrastructure cannot become an invisible gateway for surveillance abuse.
The Industry Cannot Depend on Trust Alone
The original architecture assumed that trusted operators would behave like trusted operators.
Modern threats challenge that assumption.
Today, a malicious actor may obtain access to legitimate infrastructure, use an intermediary, manipulate identifiers or exploit weaknesses in routing relationships.
Security therefore has to evolve from simply asking, “Is this network trusted?” to asking, “Can this specific request be authenticated, verified and justified?”
The Most Important Lesson for Mobile Users
Ordinary users should not read this investigation and conclude that every phone is being secretly tracked.
Citizen Lab notes that these campaigns are generally associated with targeted surveillance, particularly against high-profile individuals, and says it has not identified evidence that ordinary users were being tracked in the research described.
The larger concern is systemic.
The infrastructure exists.
The techniques are real.
And sophisticated actors have demonstrated that the global mobile ecosystem can be abused without necessarily compromising the smartphone itself.
What Undercode Say:
Deep Analysis: The Phone Is Only One Piece of the Surveillance Puzzle
The most important revelation here is not that SS7 can be abused. Security researchers have known that for years.
The important development is the evidence showing how sophisticated surveillance actors operationalize those weaknesses against real targets.
This turns an old protocol-security problem into a modern intelligence problem.
The attacks demonstrate that telecommunications infrastructure can become a surveillance platform without behaving like conventional malware.
The attacker does not necessarily need to compromise Android, iOS or a messaging application.
The attacker can instead target the systems that tell mobile networks how subscribers move between networks.
That makes the telecom ecosystem itself part of the attack surface.
The “Ghost Operator” concept is especially important because attribution becomes significantly harder when malicious traffic wears the identity of legitimate infrastructure.
This is similar to an attacker entering a building while wearing someone else’s security badge.
The badge may be genuine.
The person using it may not be.
That distinction is extraordinarily difficult to resolve when thousands of organizations exchange traffic every second.
The investigation also demonstrates why cybersecurity telemetry must be retained long enough to reveal patterns.
A single suspicious signalling event can look harmless.
Hundreds of related events spread across years can reveal an organized campaign.
This is why historical correlation is becoming increasingly important in telecommunications security.
The use of multiple protocols is another significant warning.
Security teams cannot treat SS7, Diameter and newer mobile technologies as completely isolated worlds.
Real-world networks are layered environments.
Legacy infrastructure remains connected to modern infrastructure because users still need roaming, SMS and compatibility.
Attackers understand those relationships.
They can therefore search for transitions between systems rather than attacking one technology in isolation.
The SIM-based campaign is perhaps even more disturbing because it demonstrates how an old mobile capability can become a surveillance mechanism.
The SIM was designed to authenticate and interact with mobile networks.
It was never intended to become an invisible sensor controlled by an unknown remote party.
Yet specialized commands can potentially transform trusted functionality into an attack surface.
This highlights a broader cybersecurity principle: legitimate functionality can become dangerous when an attacker gains unauthorized access to the pathway that controls it.
Another important issue is commercial access.
Telecommunications is not a completely closed environment.
There are carriers, roaming hubs, signalling providers, IPX providers, resellers, technology companies and other intermediaries.
Every additional connection creates operational complexity.
Every connection also potentially creates another security boundary that must be monitored.
This means telecom security is increasingly a supply-chain security problem.
An operator may maintain strong internal defenses while still depending on partners whose security practices are less mature.
That is why interconnect governance is just as important as firewall technology.
The research also challenges the assumption that newer generations of mobile technology automatically eliminate older threats.
5G can provide stronger security mechanisms, but global networks evolve gradually.
Legacy systems do not disappear simply because a newer standard has been deployed.
Devices roam.
Networks interconnect.
Operators maintain compatibility.
The result is a complicated ecosystem in which old and new protocols continue to coexist.
Sophisticated attackers can exploit that complexity.
The investigation also illustrates why surveillance technology is becoming increasingly difficult to distinguish from conventional network infrastructure.
The same systems that enable a phone to connect while traveling internationally can potentially be abused to identify where that phone is located.
The difference lies in who is sending the request, why it is being sent and whether the request is authorized.
That is fundamentally a governance problem.
Technical defenses alone cannot completely solve it.
There must also be accountability for who receives access to signalling networks, how that access is monitored and how suspicious traffic is investigated.
The repeated use of identifiers over several years is particularly important.
Persistence suggests that some surveillance operations are not temporary experiments.
They can become long-term capabilities.
That means defenders need long-term visibility rather than relying exclusively on real-time blocking.
The more mature surveillance becomes, the more important behavioral fingerprints become.
Timing patterns, routing characteristics, identifier reuse and unusual combinations of signalling requests can collectively reveal an actor even when individual messages appear legitimate.
This is where telecommunications threat intelligence can become extremely powerful.
Instead of asking only whether a particular message is malicious, defenders can ask whether the behavior matches a known surveillance campaign.
That is a much stronger defensive model.
The research also demonstrates why attribution should be handled carefully.
Seeing an
This distinction protects legitimate organizations from false accusations while allowing researchers to focus on the actual technical behavior.
It also demonstrates why modern cyber investigations require multiple independent data sources.
Routing data alone may not tell the whole story.
Signalling logs alone may not tell the whole story.
Public operator records alone may not tell the whole story.
But when those sources are correlated, investigators can reconstruct how suspicious traffic moved through the ecosystem.
That methodology is one of the strongest aspects of the Citizen Lab investigation.
The broader implication is uncomfortable but clear: mobile security is no longer only about protecting the phone.
It is about protecting the entire chain between the phone, its home operator, roaming partners, signalling providers and international interconnect networks.
If one link is weak, the entire chain can potentially be abused.
For governments and regulators, this should be treated as critical infrastructure security.
For operators, it should be treated as an interconnection and supply-chain security issue.
For security researchers, it represents an important area where traditional endpoint-focused approaches are insufficient.
And for users, the lesson is not panic.
The lesson is awareness.
A modern smartphone can be highly secure while still depending on infrastructure that was designed decades ago under very different assumptions.
That is the fundamental contradiction exposed by this investigation.
The phone has become more sophisticated.
The applications have become more secure.
The encryption has improved.
But the global telecommunications ecosystem still carries legacy trust relationships that can be exploited from behind the scenes.
Until those relationships are redesigned around authentication, verification and accountability, the possibility of “Ghost Operators” will remain.
Why This Matters Beyond Surveillance
This research should not be viewed only as another story about intelligence agencies or commercial spyware.
It reveals a broader cybersecurity principle: critical infrastructure can become the attack surface even when the endpoint remains untouched.
That concept applies far beyond telecommunications.
Cloud providers, identity platforms, payment networks, DNS infrastructure and software supply chains all depend on interconnected trust relationships.
When those relationships become too permissive, attackers do not necessarily need to break the strongest system.
They simply find the trusted path around it.
Telecommunications surveillance is therefore a warning about the future of cybersecurity itself.
✅ Citizen Lab did identify two sophisticated telecom surveillance campaigns and linked real-world attack traffic to mobile operator signalling infrastructure.
✅ The research documents the use of 3G SS7 and 4G Diameter techniques, including a campaign involving specially formatted SMS messages capable of interacting with SIM functionality.
✅ Citizen Lab found long-running surveillance activity and more than 15,700 location-tracking attempts associated with the STA2 campaign dating back to October 2022.
❌ The investigation does not prove that the named telecommunications operators knowingly conducted the surveillance. Citizen Lab explicitly warns that operator identifiers can be abused through spoofing, intermediaries or third-party arrangements.
❌ The research does not establish that ordinary mobile users are being mass-tracked. Citizen Lab says these campaigns typically involve targeted surveillance and that it has not identified regular users being tracked in its investigation.
Prediction
(+1) Telecommunications security will increasingly become a major focus of national cybersecurity programs as governments and operators recognize that mobile signalling infrastructure can be abused without directly compromising smartphones.
(+1) Signalling firewalls, behavioral analytics and cross-operator threat intelligence will likely become more sophisticated as defenders attempt to identify coordinated surveillance campaigns rather than isolated malicious requests.
(+1) Regulators are likely to push for stronger controls over third-party access to international signalling networks, particularly where commercial intermediaries can provide pathways into trusted telecom infrastructure.
(+1) The concept of “Ghost Operators” could become increasingly important in future threat intelligence because attackers are likely to continue hiding behind legitimate infrastructure rather than relying exclusively on obviously malicious servers.
(-1) If legacy SS7 infrastructure and weak interconnect governance remain widespread, sophisticated surveillance actors will continue to have opportunities to exploit the gap between modern mobile security and older telecommunications trust models.
(-1) Attribution will remain difficult as long as malicious traffic can be routed through legitimate operators, intermediaries and international signalling providers.
The Bigger Warning
The most frightening aspect of this investigation is not that someone discovered another vulnerability.
It is that the vulnerability exists inside infrastructure the world depends on every day.
A phone can be fully patched.
An application can be secure.
A user can avoid phishing links.
And yet surveillance can potentially occur somewhere beneath all of those protections.
Citizen Lab’s investigation shows why cybersecurity must eventually move beyond protecting individual devices and begin protecting the invisible systems that connect them. The global telecom network was built on trust. Modern surveillance actors are demonstrating what happens when that trust becomes the attack surface.
Source
Citizen Lab, Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors, published April 23, 2026.
Read the full Citizen Lab investigation
▶️ Related Video (76% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.medium.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube



