SS7 Cross-Border Location Tracking Tactics Observed Against Tier-1 Operators
Publication Date: September 10, 2026
Author: TelcoSec Threat Research Team
Advisory ID: TS-ADV-2026-003
Target Protocols: GSM MAP / TCAP / SCCP
Overview
Recent telemetry collected from international telecom signaling research nodes indicates a surge in categorized Category 1 & Category 2 GSMA FS.11 bypass maneuvers. Adversaries utilizing leased Global Title (GT) routes are chaining multiple MAP queries to bypass keyword-based signaling firewalls.
Attack Sequence Analysis
Rather than issuing single AnyTimeInterrogation (ATI) messages—which are commonly blocked by modern carrier STPs—attackers are staging queries in a three-phase reconnaissance cycle:
- Phase 1: IMSI Resolution: Sending
sendRoutingInfoForSM(SRI-SM) with randomized SCCP Calling Party Addresses (CgPA) mimicking legitimate roaming SMS centers. - Phase 2: Serving MSC/VLR Identification: Harvesting the target's current VLR address from the SRI-SM response.
- Phase 3: Real-Time Cell ID Extraction: Directly querying the visited MSC using
provideSubscriberInfo(PSI) requestinglocationInformationandageOfLocationEstimate.
Attacker (GT Leased) ----[ MAP SRI-SM ]----> Carrier HLR
Carrier HLR ----[ IMSI + VLR GT ]---> Attacker
Attacker (GT Leased) ----[ MAP PSI ]-------> Visited MSC/VLR
Visited MSC/VLR ----[ CGI (Cell ID) ]---> Attacker (Location Fixed)
Recommended Defense Configuration
- Implement GSMA FS.11 Cat 1/2/3 multi-layer filtering at all international STP / ITP edge gateways.
- Enforce strict MAP screening for PSI messages arriving from international interconnect links (PSI should never originate outside the subscriber's home network).
- Utilize TelcoChisel's
sigploitandsctpscanto continuously validate interconnect firewall policy rules.
Educational Lab Access
Full packet traces and emulation scripts are available inside the TelcoSec Academy Signaling Security Module.