FEED
Adversarial research on cellular network security — SS7 exploitation, 5G SBA vulnerabilities, and real-world threat actor intelligence documented for defenders and operators.

5G SBA NRF OAuth2 Token Abuse and NF Impersonation
How rogue NFs abuse missing NF Instance ID binding in NRF OAuth2 token issuance to impersonate AMF/UDM and exfiltrate 5G core subscriber data.
5G SEPP N32 Roaming Interface Security Bypass
How SEPP N32-c capability negotiation can be downgraded to unencrypted N32-f, letting IPX-positioned adversaries intercept roaming SBI traffic in plaintext.
5G SUCI Null-Scheme Attacks: The IMSI Catcher Evolution
APT41 (Double Dragon): When State Espionage Meets Telecom Billing Fraud
GALLIUM (Operation Soft Cell): 7 Years Inside 10 Global Carriers
MITRE FiGHT for Telecom: A Field Guide to 5G Attack Techniques
MuddyWater: Iran's Long-Running Telecom Espionage Campaign
MuddyWater (MERCURY) is an Iranian MOIS-linked APT running ongoing spearphishing and VPN-exploitation espionage against Middle East telecom operators.
RAN & Wireless Security Assessment: A Practical Methodology
Salt Typhoon: Inside the Breach That Compromised US Carrier Wiretap Systems
Sandworm: The GRU Unit Behind NotPetya Targets Telecom as a Weapon
CAMEL InitialDP Call Redirection and Charging Fraud
Diameter S6a CLR Forced Subscriber Deregistration
How adversaries abuse the Diameter S6a Cancel-Location-Request to impersonate the HSS, force subscriber detach, and stage attach-hijack race conditions.
Diameter S6a ULR Subscriber Location Disclosure
GTP-C Tunnel Hijacking and IMSI Overbilling Fraud
LightBasin (UNC1945): The APT That Lived in Roaming Networks for 5 Years
Liminal Panda: A 4-Year SS7 and Diameter Espionage Campaign
IMS SIP REGISTER Identity Spoofing in VoLTE
TelcoSec IMS SIP REGISTER spoofing analysis: how weak IMS-AKA authentication lets attackers hijack VoLTE calls, SMSoIP, and bypass OTP delivery.
SS7 MAP SMS Interception via UpdateLocation
SS7 SRI-for-SM Subscriber Geolocation Attacks
Telecom OSINT: A Reconnaissance Methodology for Carrier Infrastructure
How We Track Telecom Threat Actors: MITRE ATT&CK, FiGHT, and the Kill Chain
Volt Typhoon: Pre-Positioning for Wartime Disruption of US Telecoms
How Volt Typhoon used living-off-the-land techniques and hijacked SOHO routers to pre-position inside US telecom, energy, and water infrastructure.
10 Threat Intelligence Resources for MNO SOC Teams
Why Telecoms Outgrow Generic Threat Intelligence
Mobile Network Evolution: Understanding 3GPP Releases
Telco vs Computer Networks: Architecture & Convergence
RAN Vulnerabilities: A Deep Dive into the Air Interface
TelcoSec RAN air interface security vulnerabilities: O-RAN exploitation, IMSI catcher deployment, NAS/RRC manipulation, and MEC attack surface analysis.
5G Network Slicing Security
IMSI Catchers and Rogue Base Stations
SIM Cloning and SIM Swap Attacks
Diameter Protocol Security Analysis
SS7 Location Tracking Vulnerabilities
TelcoSec SS7 MAP exploitation guide: subscriber tracking, SMS interception, and call redirection via SendRoutingInfo and ProvideSubscriberInfo attacks.
Baseband Exploitation in Modern Smartphones
5G Network Security Architecture
Setting up a Private LTE/5G Environment
Methodology: Telecom Penetration Testing Lifecycle
Vulnerabilities in the 5G SBA
TelcoSec exposes 5G SBA vulnerabilities: NRF poisoning, BOLA in telecom APIs, container breakout paths in Kubernetes-deployed 5G cores, and zero-trust defenses.
ACCESS ADVANCED SIGNALING LABS
Our Intelligence Feed is just the beginning. Register on the platform to access full course modules, virtual labs, and real-time research nodes.














