Blog

5G Security Guidance for MNOs

Old Technology, Modern Abuse: Why SS7 Security is not Prepared for 5G

For decades, Enea has been on the frontlines of SS7 security, helping mobile network operators stay a step ahead of evolving threats. That experience has given us a deep understanding not only of the inner workings of signaling networks, but also the type of threats and adversaries looking for ways to exploit them. Few technologies illustrate the evolution and sophistication of signaling networks better than SS7.  

Originally designed for a far simpler, trust-based telecom environment, SS7 has been repeatedly extended and built upon as mobile networks have evolved, transforming it into an incredibly diverse and variable signaling ecosystem. Its legacy architecture, intrinsic complexity, and continued coexistence with newer technologies make SS7 challenging  to secure comprehensively. This raises an important question as the industry moves to 5G: can we really assume that a network that is “secure by design” will be secure against every signaling threat? 

5G undoubtedly introduces stronger security mechanisms and addresses many of the weaknesses inherent in legacy technologies, but it also introduces new architectures, interfaces, protocols and attack surfaces. Crucially, 5G deployments do not exist in isolation: they must coexist and interwork with 4G, 3G and 2G networks, meaning legacy signaling and its associated risks remain part of the security landscape. The result is a signaling environment that is more complex, and one in which new attack techniques and previously unseen vulnerabilities will inevitably emerge. For operators, the question is therefore not whether 5G is really secure by design, but whether their security controls are capable of keeping pace with the threats that 5G’s increasingly complex signaling environment will create.

SS7 in the Wild

Over the years, threat actors have demonstrated that legitimate SS7 functionality can be abused in ways that were never envisaged when the protocol was first designed. 

Threat actors operating in the signaling space, more often than not, are incredibly sophisticated, technically capable, and have access to significant resources. A proportion of signaling attacks are linked to opportunism, common fraud (like OTP interception for banking theft) and organised crime groups, but for the high-impact attacks, we are dealing with very sophisticated actors. These adversaries are often well-funded professional surveillance agencies, who are commonly serving a political agenda and backed by Nation-States. They exploit the SS7 network for things like tracking high profile political figures, intercepting communications, and gaining unauthorised access to network services. They can be profiled as follows: 

The Advanced Persistent Attacker | SS7 Security

Threat Actor Profile
Primary Objective Typically espionage, surveillance, comms interception, denial-of-service.
Targeting Highly selective and intelligence-led, with a focus on high-value individuals and strategic communications.
Tactics Abuses signaling network protocols with extreme stealth, adaptation, and network manipulation to evade signaling firewalls.
Sophistication Highly specialized, deep familiarity with telecom signaling environments.
Visibility Make every effort to evade detection and remain hidden for as long as possible.
Impact Severe: can expose critical communications, enable location tracking, and support crimes like espionage, kidnapping, high-value data theft.

From Isolated SS7 Attacks to Global Probing

While early signaling attacks were largely about exploiting legacy trust in closed telecom environments, today’s attackers operate in a far more interconnected telecom landscape. They probe and test a wide range of entry points and potential weaknesses, reaching across borders and beyond their target network in efforts to find a vulnerability they can exploit. 

 In 2022, for example, Enea detected a large-scale signaling probe conducted by a sophisticated threat actor that our team was actively monitoring. In the map below, highlighted in blue are all the countries that were targeted with probing activity. This probing was done in preparation for more targeted attacks, with multiple mobile operators being probed in each country. 

 

map of SS7 probing pertaining to SS7 security threatsGlobal SS7 Probing Activity

SS7 threats are no longer isolated attacks against individual networks. They are part of a broader, persistent process of reconnaissance, in which attackers systematically map the signaling landscape and look for weaknesses they can exploit. In an environment this complex, just one obscure or unexpected signaling behavior can become an opportunity for attack.  

How Complexity Creates Gaps in SS7 Security

 The complexity of SS7 does not just create opportunities for attackers; it also creates challenges for the systems designed to stop them. Mobile signaling standards are designed to be comprehensive: specifications from bodies such as 3GPP and the ITU are extremely detailed, defining the full range of messages, procedures, and operational scenarios that a network may encounter. Industry bodies such as the GSMA translate this detail into practical recommendations for the mobile industry, identifying the features operators should support and the controls they should apply at network boundaries. The problem is, these recommendations are not always implemented in full. Typically, functions that are commercially viable for individual mobile networks, markets and roaming relationships are prioritized, leaving less common features unsupported or only partially implemented. This is where security gaps are created: a signaling firewall may correctly parse and inspect familiar commands, but fail to recognize an unusual or newly introduced command because it lacks the feature or capability to recognize and handle such a command. In cases like this, traffic can be misclassified, allowed through without the intended security checks, or disrupted altogether. In a recent SS7 bypass attack identified by Enea’s threat intelligence experts, a malicious actor was found to be actively exploiting this security gap. In the attack, the adversary sent a fraudulent SS7 ProvideSubscriberInfo (PSI) request containing the target subscriber’s IMSI (used to identify a specific subscriber), using unusual encoding that the operator’s security system was unable to decode. The request – used by the attacker to retrieve a subscriber’s location – was allowed to pass through to the core network and return location information.  

The attack technique, however, was not universally successful – it only bypassed network controls where security nodes were not equipped to recognize and decode the unusually structured command. In the successful attack, the encoder in the network’s SS7 security system lacked that functionality, resulting in the malicious command being allowed through. Operators whose SS7 firewalls could correctly decode the command and apply the relevant checks were able to block the attack. 

 The 5G Factor

So, what happens when you take an already complex signaling environment and make it significantly more distributed, virtualised and dynamic?  We know that 5G’s built-in security features make it significantly more secure than previous generations. However, we need to acknowledge that they do not guarantee protection against every security threat. 5G introduces new interfaces, protocols, network functions and signaling interactions spanning the 5G Core, radio access network, roaming infrastructure, and cloud-native network environments. Features like network slicing, service-based architecture, edge computing, and extensive interworking with 4G and legacy networks significantly expand both the number and diversity of signaling events a security system must understand. This creates a larger and more dynamic attack surface, and more potential for gaps between the security requirements defined by industry bodies and what is actually implemented in individual operators’ security infrastructure.  

In a 5G environment, compliance with a subset of security requirements does not provide complete protection. A security system may meet compliancy requirements yet still be unable to recognize or handle an unusual signaling message or attack technique that falls outside those controls. As with the SS7 bypass example above, attackers can exploit these gaps by using signaling messages or techniques that a security system does not recognize. The more of those security gaps that inevitably emerge in 5G, the more opportunities attackers have to exploit them. For operators, this means being compliant with the relevant standards is not enough: security controls must be capable of keeping pace with the evolving signaling environment, and critically, have the intelligence to identify threats that fall outside expected or previously observed patterns.  

 With Great Connectivity Comes Great Responsibility

In an increasingly interconnected 5G world, we cannot afford to assume that existing security controls will always be sufficient to block potential signaling threats. The reality is that these threat actors often have significant resources at their disposal and are continually seeking new ways to bypass conventional firewall controls and security checks. 

Signaling threats are constantly emerging and evolving, and the greatest risk often comes from anomalous threats. New, unusual, or previously unseen behaviors that a signaling protection system has not yet been configured to recognize are the kinds of threats that attackers find the most success in. For mobile operators, combining global threat intelligence with a well-maintained, capable signaling firewall provides valuable visibility into emerging attack patterns, how they are being used elsewhere, and where existing protections may need to be strengthened. This enables operators to keep their defenses aligned with the evolving threat landscape and respond to new techniques before they become a local incident.

The Bottom Line for Mobile Network Operators

While 5G brings stronger built-in security, it also creates more opportunities for SS7 attackers to find unexpected paths through the network. For operators, the ability to adapt to this threat landscape will be critical to staying ahead of novel signaling attacks and protecting the services and customers that depend on their networks. 

In an environment where reliable connectivity is critical, even a short-lived SS7 security breach can have far-reaching consequences. For mobile operators, the impact of a successful attack can be significant – from service disruption and degraded network performance to financial losses, reputational damage, and a loss of customer trust. If a network’s signaling security lacks up-to-date threat intelligence, flexible security controls, and ongoing maintenance, the network is exposed to those risks. 

Enea works with leading MNOs to strengthen their SS7 security for 5G with real-time, intelligence-led signaling protection, helping them stay in front of evolving threats. Discover how below.