White Paper Excerpt

Excerpt 3 from Fraud Handbook

Network Messaging Fraud: Grey Routes & SIM Banks

Application-to-person (A2P) messaging (one-time passwords, banking alerts, delivery notifications, marketing, and other text messages that enterprises send to subscribers) is among the most profitable services an operator runs because each message terminating on the network should command a wholesale termination fee. When A2P messages are delivered via unofficial, lower-priced or free routes to avoid the operator’s termination fees, it is known as grey-route traffic.

Why Grey Route Fraud Exists

The A2P delivery chain can be intricate, involving several intermediaries between the brand and the operator. Typically, brands rely on a CPaaS to manage messaging, which then passes messages to aggregators that route them to the final destination. Multiple aggregators might relay the message before it reaches an aggregator with a direct connection to the operator. Unlike P2P SMS, which is usually unlimited on most plans, A2P SMS is billed per message. Billing occurs in the opposite direction of message delivery, with the operator charging a termination fee and each intermediary adding their margin. The complexity and diversity of the delivery chain allow malicious actors to send A2P SMS through unauthorized routes, such as disguising them as P2P SMS, depriving MNOs of legitimate revenue.

In recent years, the cost of sending A2P SMS has risen sharply, making gray-route fraud more profitable for fraudsters. Rising prices, together with shifting consumer behavior, have also led brands to move to other messaging channels, including messaging apps that send messages outside the A2P value chain. Both operators and aggregators are unable to monetize this messaging traffic, leading aggregators to see their volumes (and revenue) shrink. In combination with intense competition, this has led more entities in the delivery chain to use gray routes to maintain margins. This has put more stress on operators’ defenses.

How Grey Route Fraud Actually Works

Various types of grey route fraud exist, each with multiple versions and variants. Fraudsters have long used grey routes to avoid A2P SMS termination fees. As operators become more aware and implement controls to redirect unmonetized traffic to legitimate, monetized routes, these methods have evolved and become more sophisticated. Below are some of the most harmful and well-known techniques currently used by rogue actors.

SIM Boxes (Highest Harm)

SIM box bypass is most likely the form of SMS grey-route fraud that causes the greatest revenue losses for MNOs. These devices contain multiple prepaid P2P SIM cards connected to a server that acts as a “grey route traffic machine.” Incoming A2P traffic from brands is diverted to the SIM box, which then sends the traffic out again as if it were a local mobile-originated session. As one SIM box can support hundreds of SIM cards, and SIM boxes can be combined to build even bigger pools, traditional hardware-based SIM boxes are used by professionalized fraudsters offering significant capacity.

There are also more modern versions of this fraud. For years, apps have existed for mobile phones that function as single-SIM boxes. These apps work by having users install them and then use their phones’ SIM cards to automatically send A2P messages over the P2P path, with users earning small rewards for messages sent through the app. The users have no control over the traffic passing through their phones. Another variation involves installing a mobile phone app that allows the user to send A2P messages via an API. In this case, the user is the sender, but the method still bypasses the operator’s approved paths and billing for A2P messaging. Essentially, it turns the phone into the user’s own CPaaS infrastructure.

Masquerading A2P traffic as P2P

Rogue aggregators can blend A2P messages into P2P traffic and route it through pathways intended for mobile-originated SMS, which often have lower or no inter-operator fees. One mechanism to accomplish this is to exploit telecom-to-telecom roaming agreements intended for P2P messages, which typically have a 1:1 imbalance tolerance and no inter-operator fees. By disguising application-to-person (A2P) traffic as person-to-person (P2P), they monetize the traffic on one side while the other operator doesn’t charge. It is also common to replace international sender IDs with local ones and route messages through domestic networks, making the traffic appear as if it originates from a local user and helping it fit into P2P routing patterns while bypassing the operator’s A2P pricing and controls.

Routing Through Unofficial Paths A2P Aggregators-Routing (High Harm)

Aggregators send SMS on grey routes by using indirect, non-contracted pathways that bypass the destination operator’s agreed interconnect or direct A2P routes, typically to reduce cost or avoid fees. They do this by leveraging other aggregators or hops in a least-cost routing (LCR) strategy, where an aggregator passes traffic through multiple downstream aggregators or “hops” instead of using a direct route. This traffic is often sent across multiple countries to reach the destination at a lower price, but it is no longer on a sanctioned path and may be unreliable. In parallel, aggregators may exploit a local aggregator in the destination market that has better SMS rates than the operator’s own agreement, routing A2P traffic via that local aggregator so the originating operator avoids paying the agreed price and the destination operator loses revenue. Both approaches rely on indirect, non-contracted pathways that circumvent the destination operator’s normal interconnect arrangements.

Why Grey Routes Can Be Hard to Detect

The primary challenges are that grey route SMS initially appears similar to legitimate traffic, new campaigns with new content from new brands emerge frequently, and fraudsters are incredibly fast to move traffic to new routes when others become blocked. As a result, operators must rely on multiple indirect indicators to identify them. In practice, detection is difficult because these routes are deliberately obscured and the traffic is often blended with P2P flows.

  • It is blended. Grey traffic is often blended with white traffic, making it harder to distinguish legitimate A2P messaging from fraudulent or unauthorized routing based on traffic patterns alone. Hiding grey traffic amid large message volumes is easy for rogue senders, making detection through traffic-pattern anomalies harder.
  • No single ground truth marker. Grey route traffic can mimic normal delivery behavior and sender patterns, so it is not reliably detectable from a single identifier. Keyword identification alone is unreliable and risks creating false positives.
  • Hidden or changing paths. Messages are often routed through multiple intermediaries and use different routes even when the sender and recipient are the same. Rogue entities can hide in this complex web by masking the message’s true path, making it harder to determine what to block.
  • Fast adaptation by fraudsters. As operators block one route, traffickers switch routes or infrastructure, so detection models and rules can become stale quickly. Operators need to know where the grey traffic is and when.
  • Operational trade-offs. Aggressive blocking or blunt detection methods risk false positives against legitimate A2P traffic, so operators need high precision before enforcement.

Since grey route traffic imitates legitimate activity, uses multiple network paths, and quickly adapts, it is inherently challenging to identify. Effective detection depends on ongoing, behavior-based analysis instead of static filters or rule-based methods.

Classes of Defense Against Grey Route Traffic

Detecting grey route traffic typically relies on a combination of complementary control approaches, each addressing different aspects of how this traffic hides within legitimate flows. As inputs, either behavior-based detection, such as traffic volumes and sending times from specific senders, or content-based detection can be used. In reality, a combination of both is needed.

  • Network / source-based controls (e.g., GT blocking). Operators block or restrict traffic from specific networks or routes identified as suspicious. This is a blunt method that assumes all traffic from the same source is grey, which is rarely the case, making it prone to blocking legitimate traffic as well. If all traffic from the source is in fact grey, then it can be an effective method, but only if the operator can immediately detect it as fraudsters move traffic to another source.
  • Identity-based controls (sender ID/origin filtering). Filters are applied to alphanumeric sender IDs or originating addresses. Identifying rogue senders can be more granular than identifying network sources, and the risk of blocking legitimate traffic is reduced. However, for efficiency, operators need to know what to look for, as switching to another sender ID is even quicker than switching the network source, and fraudsters frequently use identity rotation or spoofing to bypass filters.
  • Message-based detection (keywords/pattern matching). Message-based detection enables filtering at the individual-message level. This is needed when A2P traffic is blended with P2P traffic to avoid blocking legitimate messages. Often, messages are analyzed for known spam keywords or for the brand that sent them. However, if filters are set up based on a one-time initial analysis of traffic, or traffic is analyzed at regular intervals to find keywords, this leaves significant gaps during which traffic can pass with only minor changes. Continuous monitoring and adaptation of filters are needed to keep defenses up-to-date.

Many approaches deployed by operators rely on static rules, prior knowledge, and periodic analysis, making them inherently reactive. As grey route traffic is dynamic, distributed, and often embedded in legitimate flows, these controls create a trade-off between protection effectiveness and revenue/customer impact.

How Enea Fits In

Enea’s approach to grey route detection and control is based on threat intelligence to know where, when, and how grey traffic emerges across an operator’s entry points, and message-level filtering.

  • Enea performs continuous, intelligence-driven detection instead of periodic analysis. It monitors live traffic constantly, identifying grey route activity as it occurs rather than after patterns cause revenue loss. This enables quicker detection and a smaller window for evasion. Rather than depending on fixed rules, such as known GTs or keywords, Enea employs real-time traffic profiling and automatic content discovery to analyze traffic behavior and changes.
  • Enea’s approach focuses on behavioral and content intelligence, analyzing each message to differentiate legitimate traffic from grey traffic, even if both come from the same connection. This granular analysis allows Enea to target and block only the grey traffic components, leaving legitimate business traffic unaffected. It can detect and block new, unseen grey routes without prior knowledge. Consequently, grey traffic hidden within trusted or compromised channels remains identifiable.

For operators, the ability of a grey route SMS firewall to effectively detect and block unmonetized traffic is crucial for A2P SMS revenue. Improving detection effectiveness from 80% to 90% can yield an additional USD 45 million in annual earnings for a large operator. Since many available firewalls detect fewer than 80% of attacks, switching vendors can significantly increase the amount of traffic monetized and, in turn, revenue.

Enea detects more grey traffic because it shifts from static, rule-based filtering to dynamic, behavior-driven, real-time intelligence applied at the message level across the entire network. This removes the blind spots that traditional approaches leave open.

Handbook Detecting and Countering Fraud and Revenue Leakage in Mobile Networks