SS7 Cross-Border Location Tracking Tactics Observed Against Tier-1 Operators

Publication Date: September 10, 2026
Author: TelcoSec Threat Research Team
Advisory ID: TS-ADV-2026-003
Target Protocols: GSM MAP / TCAP / SCCP

Overview

Recent telemetry collected from international telecom signaling research nodes indicates a surge in categorized Category 1 & Category 2 GSMA FS.11 bypass maneuvers. Adversaries utilizing leased Global Title (GT) routes are chaining multiple MAP queries to bypass keyword-based signaling firewalls.

Attack Sequence Analysis

Rather than issuing single AnyTimeInterrogation (ATI) messages—which are commonly blocked by modern carrier STPs—attackers are staging queries in a three-phase reconnaissance cycle:

  1. Phase 1: IMSI Resolution: Sending sendRoutingInfoForSM (SRI-SM) with randomized SCCP Calling Party Addresses (CgPA) mimicking legitimate roaming SMS centers.
  2. Phase 2: Serving MSC/VLR Identification: Harvesting the target's current VLR address from the SRI-SM response.
  3. Phase 3: Real-Time Cell ID Extraction: Directly querying the visited MSC using provideSubscriberInfo (PSI) requesting locationInformation and ageOfLocationEstimate.
Attacker (GT Leased) ----[ MAP SRI-SM ]----> Carrier HLR
Carrier HLR        ----[ IMSI + VLR GT ]---> Attacker
Attacker (GT Leased) ----[ MAP PSI ]-------> Visited MSC/VLR
Visited MSC/VLR    ----[ CGI (Cell ID) ]---> Attacker (Location Fixed)
  • Implement GSMA FS.11 Cat 1/2/3 multi-layer filtering at all international STP / ITP edge gateways.
  • Enforce strict MAP screening for PSI messages arriving from international interconnect links (PSI should never originate outside the subscriber's home network).
  • Utilize TelcoChisel's sigploit and sctpscan to continuously validate interconnect firewall policy rules.

Educational Lab Access

Full packet traces and emulation scripts are available inside the TelcoSec Academy Signaling Security Module.