Unveiling the Ghosts of Mobile Networks: When Will Old Bugs Die?
Dr Altaf Shaik (Senior Researcher · Technical University of Berlin)
44CON 2024 · Day 3 · Main
Overview
Dr. Altaf Shaik's talk, "Unveiling the Ghosts of Mobile Networks: When Will Old Bugs Die?", delivers a sobering assessment of the enduring security vulnerabilities plaguing mobile communication networks, from 2G to the nascent 5G. As a seasoned telecom expert, Dr. Shaik highlights a critical and often overlooked problem: the tendency of network operators and vendors to apply superficial patches rather than addressing the fundamental root causes of security flaws. This approach inadvertently allows "old bugs" to resurface, sometimes in new forms, across successive generations of mobile technology, undermining the promise of enhanced security in modern networks.

Key moments
- 0:00 Introduction and the problem of persistent telecom bugs
- 2:00 Overview of classic telecom attacks and IMSI catchers
- 3:20 Exploiting SS7/Diameter interconnects for location and interception
- 4:30 Mobile network evolution: 5G security expectations versus reality
- 6:00 Why old vulnerabilities persist even in 5G networks
- 6:40 Hardware and software setup for mobile network testing
Unveiling the Ghosts of Mobile Networks: When Will Old Bugs Die?
Speakers: Dr Altaf Shaik, Senior Researcher, Technical University of Berlin
Conference: 44CON
YouTube: https://www.youtube.com/watch?v=364R1SoGGJ4
Overview
Dr. Altaf Shaik's talk, "Unveiling the Ghosts of Mobile Networks: When Will Old Bugs Die?", delivers a sobering assessment of the enduring security vulnerabilities plaguing mobile communication networks, from 2G to the nascent 5G. As a seasoned telecom expert, Dr. Shaik highlights a critical and often overlooked problem: the tendency of network operators and vendors to apply superficial patches rather than addressing the fundamental root causes of security flaws. This approach inadvertently allows "old bugs" to resurface, sometimes in new forms, across successive generations of mobile technology, undermining the promise of enhanced security in modern networks.
The presentation delves into a comprehensive analysis of persistent weaknesses in authentication, privacy, encryption, integrity protection, and service availability, demonstrating how established attack vectors like IMSI catchers and SS7/Diameter exploits remain potent threats. Dr. Shaik also sheds light on emerging risks introduced by 5G's architecture, particularly its reliance on IT-centric protocols and the integration of IoT platforms, which expose new attack surfaces through APIs. His findings underscore the urgent need for a paradigm shift towards a zero-trust model, rigorous security testing, and a collective commitment to robust security practices across the entire mobile ecosystem.
This article provides a detailed exploration of Dr. Shaik's research, outlining the technical specifics of these vulnerabilities, their implications for users and critical infrastructure, and actionable recommendations for defenders. It serves as a stark reminder that despite advancements, the foundational security of our mobile communications remains compromised by issues that should have been long resolved, posing significant risks to privacy, data integrity, and national security.
Background
▶ Watch: Introduction and the problem of persistent telecom bugs (0:00)
The evolution of mobile networks, from 2G's nascent digital capabilities to 5G's promise of ultra-fast, low-latency connectivity, has consistently been accompanied by expectations of improved security. Each new generation, theoretically, builds upon the lessons learned from its predecessors, incorporating stronger cryptographic algorithms, more robust authentication mechanisms, and enhanced privacy features. However, as Dr. Shaik illustrates, the reality often falls short of this ideal, with fundamental security flaws persisting and reappearing across generations.
Classic telecommunications attacks, such as denial of service (DoS), interception, tracking, manipulation, backdoors, and intrusion, have been a constant concern. Two primary vectors have historically enabled many of these attacks: IMSI catchers and the exploitation of interconnect networks like Signaling System 7 (SS7) and its successor, Diameter.
IMSI catchers, also known as "Stingrays," are devices that mimic legitimate base stations to intercept mobile phone traffic. They operate in various modes: passive (capturing information), semi-passive (injecting data), and active (offering a full network, potentially routing calls/SMS through real networks or enabling mass spamming, as seen with recent SMS bluffs). Crucially, despite the advancements to 5G, IMSI catchers remain relevant due to the possibility of downgrade attacks, forcing modern phones to connect to weaker, more vulnerable older generation networks.
The SS7 protocol, developed in the 1970s, forms the backbone of global roaming, connecting different mobile operators. Its inherent design, based on implicit trust, has made it notoriously vulnerable. For over two decades, SS7 exploits have allowed attackers to disclose subscriber locations, tap phone calls, and intercept SMS messages. The proliferation of private companies offering SS7 access has democratized these capabilities, making sophisticated attacks accessible with minimal equipment, often just a simple PC, provided firewalls are not adequately configured. The successor to SS7 in LTE networks is Diameter, and in 5G, a completely new version called Secure Edge Protection Proxy (SEPP) is introduced, though Dr. Shaik notes that many underlying protocols with a history of attacks, such as GTP (GPRS Tunnelling Protocol) and Diameter, persist in 5G.
While higher generations boast stronger cryptography and improved data rates, the core operations remain largely similar. Mobile phones, base stations, and core networks all share architectural commonalities. A significant concern is the black-box nature of basebands in handsets and network equipment, which are complex to reverse engineer and can harbor backdoors, further complicating efforts to secure the mobile ecosystem. The expectation that 5G would rectify these historical issues, leveraging learnings from 2G, 3G, and 4G, forms the central tension of Dr. Shaik's investigation: why do these "ghosts" of old bugs continue to haunt our most advanced mobile networks?
Key Findings
▶ Watch: Exploiting SS7/Diameter interconnects for location and interception (3:20)
Dr. Shaik's extensive research, spanning over a decade and covering numerous networks globally, reveals a pattern of persistent, recurring vulnerabilities across mobile network generations. His key findings highlight critical shortcomings in fundamental security mechanisms:
- Infrequent Authentication and Key Reuse: Authentication often occurs only once when a phone initially connects, leading to the reuse of the same cryptographic keys for extended periods (hours or even days) in 2G, 3G, and 4G networks. This undermines the security of communication sessions.
- Non-Random Temporary Identifiers (TMSI): Despite the design intent for temporary identifiers to be random for privacy, Dr. Shaik observed predictable patterns in TMSI assignment in 2G (2015) which, alarmingly, reappeared in 5G Standalone (SA) networks, indicating a failure to address the root cause of non-randomness.
- Silent SMS and Location Tracking: The widespread use of silent SMS triggered via SS7 exploits allows for covert tracking of users, as phones do not notify the user of their receipt, compromising privacy without user awareness.
- Encryption Downgrade Attacks: Networks frequently support weak or null encryption algorithms. In 2G, it's possible to force phones to use A5/0 (no encryption) or A5/1 (easily interceptable). Even in 4G and 5G, some networks were found to operate with null encryption, often due to misconfiguration or man-in-the-middle manipulation.
- Lack of User Encryption Indicators: Unlike web browsers, modern Android and iOS devices lack visual indicators to inform users if their mobile calls or data sessions are unencrypted, leaving them unaware of compromised security.
- Integrity Protection Bypass: While 3G and 4G introduced integrity protection, some networks allow connections from devices that declare no support for it, enabling attackers to manipulate communication without detection, potentially leading to impersonation.
- Service Availability Downgrade: A simple message can force a 5G-enabled phone to downgrade its connection to 2G, exposing it to the full spectrum of older, weaker network vulnerabilities. This is an architectural flaw, not just an implementation bug.
- Persistent SMS Fraud Vectors: The SMS ecosystem remains highly vulnerable to spoofing, spamming, and sophisticated attacks like WAP push SMS containing malicious links. Operating systems often fail to display the true sender of such messages, making them appear legitimate and facilitating identity fraud and data theft.
- Exposed Network Infrastructure: Reconnaissance techniques (ping, traceroute, Nmap-style attacks) revealed that in 7 out of 12 tested networks (2G, LTE, NB-IoT), internal maintenance portals (SSH-based) were accessible from the mobile network, and unprovisioned SIM cards could perform reconnaissance traffic without being billed.
- Caller ID Spoofing in Voice over Wi-Fi: Exploiting SIP protocols, it was possible to spoof caller IDs in voice-over-Wi-Fi calls, allowing attackers to impersonate others.
- New 5G and IoT Platform Vulnerabilities: Despite 5G's advanced security features, early implementations show critical flaws, including authentication bypasses in popular handsets, and failures to activate encryption. IoT platforms, integrating directly with mobile core networks via APIs, exhibit common web vulnerabilities, including OWASP Top 10 issues like broken authorization and allowing weak passwords.
- 5G NSA vs. SA Security Disparity: Many of the enhanced security features of 5G are only available in the Standalone (SA) mode, not the more commonly deployed Non-Standalone (NSA) mode, leaving a significant portion of early 5G deployments less secure than advertised.
These findings collectively paint a picture of systemic security neglect, where fundamental principles are overlooked, implementations are flawed, and the complex interplay of new and old technologies creates an ever-expanding attack surface.
Technical Deep Dive
▶ Watch: Mobile network evolution: 5G security expectations versus reality (4:30)
Dr. Shaik's technical deep dive unpacks the mechanisms behind these persistent vulnerabilities, providing concrete examples and observations from his testing. His methodology involved a blend of active and passive analysis, leveraging specialized hardware and software to interact with live mobile networks.
IMSI Catchers and Downgrade Attacks
IMSI catchers exploit the mobile network's authentication process. In 2G, they can act as a false base station, tricking phones into connecting, then extracting the International Mobile Subscriber Identity (IMSI). Dr. Shaik explains that these devices operate in three modes:
- Passive: Simply sniffing traffic without interaction.
- Semi-Passive: Injecting specific messages to prompt responses.
- Active: Functioning as a full network, potentially routing calls or sending mass spam SMS.
The critical point for 5G is the downgrade possibility. Even a 5G phone can be forced to connect to a 2G network, where these well-established IMSI catcher techniques become fully effective. This is often achieved by manipulating signal strength or network capabilities, making the phone believe a 2G network is the only viable option.
SS7, Diameter, and Interconnect Exploits
The SS7 protocol, designed for signaling between network elements, was built on an implicit trust model. This means that once an SS7 connection is established, the communicating entities assume each other's legitimacy. This trust model is fundamentally flawed in an adversarial environment. Attackers can leverage SS7 messages to:
- Location Disclosure: Sending
Send Routing Informationmessages to ascertain a subscriber's location. - Call Tapping/SMS Interception: Diverting calls or SMS by manipulating routing information or forwarding messages.
- Silent SMS: Using SS7 to send specific messages that trigger phone actions (like location updates) without user notification.
Diameter, the successor for 4G LTE, introduces more robust security features but still carries some of the architectural baggage. In 5G, the Secure Edge Protection Proxy (SEPP) aims to secure interconnects, but the reliance on protocols like GTP and Diameter means that the historical vulnerabilities are not entirely eradicated and new attack surfaces emerge with the shift to IT-based protocols (HTTP, REST APIs).
Authentication Flaws and Key Reuse
A core finding is the lack of frequent re-authentication. Dr. Shaik observed that once a mobile phone connects to a network, authentication often occurs only once per session or day. This is analogous to TLS (Transport Layer Security), where frequent re-negotiation generates fresh session keys. In mobile networks, infrequent authentication means cryptographic keys are reused for extended periods. If these keys are compromised, an attacker gains prolonged access. He presented a 2G capture showing a ciphering mode command but no subsequent authentication, indicating key reuse. Conversely, another operator showed frequent re-authentication, demonstrating best practice. The speaker posits that energy consumption might be a reason for this neglect, but argues it's not an acceptable excuse for compromising security.
Privacy Leaks: TMSI and Silent SMS
Mobile networks use Temporary Mobile Subscriber Identities (TMSI) to protect the permanent IMSI from being broadcast over the air. The effectiveness of TMSI relies on its randomness. Dr. Shaik's analysis revealed a concerning lack of randomness. In 2015, 2G networks exhibited predictable patterns in TMSI assignment. Alarmingly, the same pattern was observed in 5G SA networks, indicating a failure to implement proper random identifier generation at a fundamental level. This means an attacker observing TMSI can potentially track a user over time.
Silent SMS, triggered via SS7, force a phone to perform actions (e.g., location updates) without user notification. This allows covert tracking. Dr. Shaik notes that the phone's GPS chip might briefly activate, but without user-facing indicators, the user remains oblivious to being tracked.
Encryption Downgrades
The talk detailed the critical issue of encryption downgrades, particularly in 2G networks. The A5/x algorithms are used for ciphering in GSM:
- A5/0: No encryption.
- A5/1: Weak encryption, demonstrated to be interceptable years ago.
- A5/2: Even weaker, exported for specific regions.
- A5/3 (KASUMI): Stronger, widely used.
- A5/4 (SNOW 3G): Modernized version.
Dr. Shaik showed that by using a modified Motorola phone, he could force almost all tested 2G networks to use A5/0 (null encryption). This is because the network, when faced with a device declaring no supported security algorithms, defaults to the lowest common denominator. Similarly, A5/1 was also commonly supported. The absence of a user-facing indicator on modern smartphones (unlike old Nokia phones) means users have no way of knowing if their calls are encrypted. Even in 4G and 5G, null encryption was observed in some networks, which operators sometimes dismissed as "test networks," despite being in production.
Integrity Protection Bypass
Integrity protection ensures that communication has not been tampered with in transit. It's absent in 2G, but present in 3G (using a Message Authentication Code - MAC) and significantly enhanced in 4G. However, Dr. Shaik found that some networks allow devices to register even if they declare no support for integrity protection. This vulnerability, first discovered in 2014 and partially addressed around 2019, allows an attacker who has stolen authentication material (not necessarily the SIM card) to impersonate a legitimate user and manipulate messages without detection. The massive scale of base station updates required makes this a slow and costly fix.
SMS Exploitation
SMS, an old technology, remains a significant attack vector. Dr. Shaik categorized various types of SMS beyond normal text messages: silent, spam, WAP push, and SIM-specific SMS. Sending these often requires specialized modems rather than standard handsets. He demonstrated how WAP push SMS, which can contain embedded links, can be used for phishing. A critical observation was that when a WAP push SMS arrives, even if from an unknown number, the phone's OS (e.g., Android) often fails to display the sender's number when attempting to save the contact, making the message appear more legitimate (e.g., from "Service n" instead of a random number), thus increasing the likelihood of user interaction with malicious links.
Network Reconnaissance and Exposure
Using traditional IT security tools like ping and Nmap, Dr. Shaik's team conducted reconnaissance within mobile network backends via the mobile interface. In 7 out of 12 tested networks (2G, LTE, NB-IoT), they found that internal maintenance portals accessible via SSH were exposed. They could also perform traceroutes and discover other mobile phones and middle boxes, some displaying legal banners. A particularly concerning finding was that SIM cards without any data plan or credit could still perform reconnaissance traffic, which was not billed, suggesting a fundamental oversight in network segmentation and access control.
5G and IoT Platform Security
5G's architecture, heavily reliant on IT-centric protocols (HTTP, REST API, JSON, containers), introduces new attack surfaces. While standards recommend TLS and IPsec, implementations are lagging. Dr. Shaik reported authentication bypasses and security mode command bypasses in new 5G handsets.
For IoT platforms, which provide APIs for external applications to control devices (e.g., video surveillance, fleet management), Dr. Shaik's team found critical vulnerabilities, including OWASP Top 10 issues like broken authorization and platforms allowing the use of weak passwords. This direct API access from external entities into the mobile core creates a new, high-stakes security frontier that is currently undermanaged.
Demo / Proof of Concept
▶ Watch: Why old vulnerabilities persist even in 5G networks (6:00)
While Dr. Shaik's presentation did not include a live, real-time demonstration, his talk was rich with evidence derived from extensive practical testing and proof-of-concept (PoC) activities. He meticulously detailed his testing methodology and presented numerous traces and observations as empirical proof of the vulnerabilities discussed.
His "kit" for testing encompassed a range of specialized equipment:
- Motorola Handsets: Specifically, older models that are highly effective for testing 2G networks due to their low-level control capabilities. Dr. Shaik humorously noted he bought about 50 of them, making them scarce on eBay, and cautioned about their aging batteries.
- Software Defined Radio (SDR): Essential for passively sniffing and actively interacting with radio signals across different generations.
- GPS Disciplined Oscillator (GPSDO): Used with the SDR to achieve highly accurate clock synchronization, crucial for precise control and analysis of mobile network timing.
- Multiple Mobile Phones: For testing various device behaviors and interactions.
- Powerful Laptop: For data processing, running SDR software, and analysis.
- Specialized Modem: For sending abnormal or specific SMS types (e.g., silent, WAP push) that cannot be generated by standard handsets.
- Faraday Cage: Used for controlled testing environments to isolate radio signals and prevent interference or unintended network interaction.
Dr. Shaik's testing focused on various aspects: calls, SMS, data, voice over Wi-Fi, and IoT. He collected information through direct captures, penetration tests for clients, and by hosting sensors in different geographical locations (with client assistance) to gather data from diverse networks. He also referenced knowledge sources like GSM map, though noting it was outdated.
The "demo" aspect of his talk primarily consisted of presenting screenshots of network traces (e.g., 2G authentication flows, A5/x ciphering negotiations) and visualizations of data patterns (e.g., TMSI randomness graphs from 2015, 2020, and 5G SA). For instance, he showed a 2G trace illustrating a connection without re-authentication and contrasted it with a trace from an operator that performed regular re-authentication. He also showed a 2G trace where the mobile phone was forced to use A5/0 encryption, and lamented the absence of a "lock" icon on modern phones to indicate unencrypted calls, a feature present in older Nokia handsets.
His PoC for SMS exploitation involved sending WAP push SMS and observing how the phone's operating system failed to display the sender's number, making the message appear more legitimate to the user. For network exposure, he described performing traditional ping scans and Nmap-style attacks from a connected mobile phone, discovering accessible SSH maintenance portals and other network elements. These practical experiments underpinned his findings, demonstrating the feasibility and pervasiveness of the vulnerabilities.
Defensive Implications
▶ Watch: Hardware and software setup for mobile network testing (6:40)
Dr. Shaik's research provides critical insights for network operators, equipment vendors, regulators, and even end-users to bolster mobile network security. The core message is a call to move beyond superficial patching and address the fundamental architectural and implementation flaws that allow old bugs to persist.
- Prioritize Root Cause Fixes: Vendors and operators must shift from merely patching symptoms to identifying and rectifying the underlying causes of vulnerabilities. This requires a deeper understanding of 3GPP specifications and their secure implementation.
- Enforce Frequent Authentication and Key Generation: Networks should be configured to perform re-authentication more frequently, ideally generating fresh cryptographic keys for each session or at regular, short intervals. This aligns with modern security best practices seen in protocols like TLS.
- Implement Robust Random Identifier Generation: Ensure that temporary identifiers like TMSI are truly random and frequently updated to prevent subscriber tracking. The observed recurrence of non-random patterns in 5G SA is a critical failure that needs immediate correction.
- Eliminate Weak Encryption Algorithms: Operators must disable support for outdated and compromised encryption algorithms, such as A5/0 and A5/1 in 2G, and actively prevent downgrade attacks to null encryption in 4G and 5G.
- Enforce Integrity Protection: Networks must strictly enforce integrity protection for all control plane and user plane traffic where applicable (3G, 4G, 5G), disallowing connections from devices that do not support it. This prevents message manipulation and impersonation.
- Enhance SMS Security: Implement robust SMS firewalls and filtering mechanisms to detect and prevent spoofed, spam, and malicious WAP push SMS. Mobile OS developers should also improve user interface design to clearly display sender information, especially for potentially malicious messages, and provide indicators for unencrypted communications.
- Secure Network Backends: Implement strict network segmentation and access controls for backend infrastructure. Maintenance portals (e.g., SSH) must not be accessible from the public mobile network. Regular penetration testing and vulnerability scanning of internal network elements, even with unprovisioned SIM cards, should be standard practice.
- Strengthen 5G and IoT API Security: With 5G's IT-centric core and the proliferation of IoT platforms, API security becomes paramount. Implement OWASP Top 10 best practices, enforce strong authorization, and mandate robust password policies. Continuous security testing of APIs is essential.
- Adopt a Zero-Trust Model: The implicit trust inherent in older telecom network designs is a critical vulnerability. Operators should transition towards a zero-trust architecture, where no entity, internal or external, is inherently trusted.
- Improve Supply Chain Security: Rigorous security testing and auditing of all network equipment, from handsets to core network components, is vital to mitigate risks from backdoors and supply chain compromises.
- Continuous Monitoring and Testing: Beyond compliance, operators need to establish continuous monitoring of network traffic for anomalies and proactive security testing across the entire chain – handset, RAN, core, and interconnect.
- Regulatory and Policy Enforcement: Governments and regulators should impose stricter penalties for security negligence. They also need to balance law enforcement's needs for lawful interception with the fundamental right to secure communications, ensuring that "backdoors" are not mandated or implicitly allowed to exist.
- Skill Development: Address the skill shortage by investing in training for engineers to develop in-depth 3GPP specification knowledge and advanced security testing expertise.
By implementing these defensive strategies, the mobile ecosystem can begin to shed the "ghosts" of old bugs and build a truly secure foundation for future generations of communication.
Key Takeaways
- Persistent Vulnerabilities Across Generations: Many fundamental security flaws, such as infrequent authentication, non-random identifiers, and weak encryption, persist and recur across 2G, 3G, 4G, and even 5G networks, indicating a failure to address root causes.
- IMSI Catchers and SS7/Diameter Remain Potent: Established attack vectors like IMSI catchers (enabled by downgrade attacks) and SS7/Diameter exploits (for location tracking, call interception, and silent SMS) continue to be highly effective due to these enduring weaknesses.
- Critical Security Features Are Often Flawed: Authentication is often infrequent, cryptographic keys are reused, privacy is compromised by non-random temporary identifiers, and encryption can be downgraded or is entirely absent in many network implementations.
- New 5G and IoT Attack Surfaces: The shift to an IT-centric 5G core introduces new vulnerabilities via HTTP, REST APIs, and containerization, while IoT platforms expose the mobile core to OWASP Top 10-style API security flaws.
- Lack of Transparency for Users: Modern mobile operating systems often fail to inform users about critical security states, such as unencrypted calls or the true sender of malicious SMS, leaving them vulnerable and unaware.
- Urgent Need for Zero-Trust and Rigorous Testing: Mobile operators and vendors must abandon the implicit trust model, adopt zero-trust principles, invest in continuous security monitoring, implement robust firewalls, and perform comprehensive, beyond-compliance testing across the entire network chain.
About the Speaker(s)
Dr. Altaf Shaik is a distinguished Senior Researcher at the Technical University of Berlin, bringing over 12 years of specialized expertise in telecommunications security. His journey began with passively sniffing 2G networks, which laid the foundation for his deep understanding of mobile communication vulnerabilities. He subsequently earned his PhD, focusing on 4G security, and has since expanded his research to include cutting-edge areas such as 6G and Open RAN security. Dr. Shaik is recognized as a leading authority in the field, dedicated to uncovering and addressing the pervasive security challenges within global mobile networks.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Shaik brings 12+ years of hands-on telecom security research to a problem most of the industry would rather ignore: the systematic failure to kill vulnerabilities across generations rather than patch them cosmetically. The longitudinal data — same TMSI non-randomness patterns appearing in 5G SA that he documented in 2G in 2015 — is the kind of empirical receipts that make standardization bodies uncomfortable, which is exactly the point.
Heather Calloway (CISO) — WEAK
Twelve years of legitimate telecom security research compressed into a catalog of known problems with no institutional diagnosis and no decision path. The vulnerabilities are real, the pattern is damning, but the talk never answers the question that matters: who owns this, and what should they do Monday morning.