216.73.216.233

T1430.002: Impersonate SS7 Nodes

View on MITRE ATT&CK The MITRE Corporation · Published 05/04/2022 21:49 · Modified 27/03/2026 01:41

Essential information

MITRE technique ID
T1430.002
Confidence
100/100
Revoked
No
Published
05/04/2022 21:49
Modified
27/03/2026 01:41
Author / Source
The MITRE Corporation

Platforms

android iOS

Description

Adversaries may exploit the lack of authentication in signaling system network nodes to track the location of mobile devices by impersonating a node.(Citation: Engel-SS7)(Citation: Engel-SS7-2008)(Citation: 3GPP-Security)(Citation: Positive-SS7)(Citation: CSRIC5-WG10-FinalReport) By providing the victim’s MSISDN (phone number) and impersonating network internal nodes to query subscriber information from other nodes, adversaries may use data collected from each hop to eventually determine the device’s geographical cell area or nearest cell tower.(Citation: Engel-SS7)

Kill chain phases

Kill chainPhase
mitre-mobile-attack collection
mitre-mobile-attack discovery

Marking (TLP)

Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references