Skip to content
Every technique
T1430.002Not expressible in SigmaMOBILE

Impersonate SS7 Nodes

Collection · DiscoveryAndroid, iOS

Where this stands

No Sigma rule can address this — the telemetry MITRE names has no Sigma logsource behind it.

Sigma has no logsource taxonomy for mobile platforms. MITRE's telemetry here is mobile EDR and device APIs, which no Sigma rule can address.

What the technique is

Adversaries may exploit the lack of authentication in signaling system network nodes to track the location of mobile devices by impersonating a node. By providing the victim’s MSISDN (phone number) and impersonating network internal nodes to query subscriber information from other nodes, adversaries may use data collected from each hop to eventually determine the device’s geographical cell area or nearest cell tower.

Read it on attack.mitre.org

What MITRE says you would watch

  • AN1753

    Defender observes anomalous signaling network queries targeting subscriber information associated with a device, including unexpected routing requests, location information exchanges, or node-origin inconsistencies indicative of SS7 signaling abuse. The CSRIC also suggests threat information sharing between telecommunications industry members.

  • AN1754

    Defender observes anomalous signaling interactions involving subscriber identity or location resolution events associated with a device, including abnormal routing requests, unexpected location information exchanges, or signaling node inconsistencies indicative of SS7 abuse. The CSRIC also suggests threat information sharing between telecommunications industry members.

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.