<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Vikas's Blog]]></title><description><![CDATA[Vikas's Blog]]></description><link>https://vikaskumar75.hashnode.dev</link><generator>RSS for Node</generator><lastBuildDate>Wed, 09 Sep 2026 13:25:23 GMT</lastBuildDate><atom:link href="https://vikaskumar75.hashnode.dev/rss.xml" rel="self" type="application/rss+xml"/><language><![CDATA[en]]></language><ttl>60</ttl><item><title><![CDATA[SS7: The Invisible Threat Behind Your Phone Calls]]></title><description><![CDATA[What is SS7?
Signalling System No. 7, or simply SS7, is a worldwide telecommunications protocol for managing the routing of phone calls, SMS messages, and other services between a network of interconnected signalling points. SS7 facilitates quick com...]]></description><link>https://vikaskumar75.hashnode.dev/ss7-the-invisible-threat-behind-your-phone-calls</link><guid isPermaLink="true">https://vikaskumar75.hashnode.dev/ss7-the-invisible-threat-behind-your-phone-calls</guid><category><![CDATA[phone calls]]></category><category><![CDATA[internet calling]]></category><category><![CDATA[Signalling System No. 7]]></category><category><![CDATA[ss7]]></category><category><![CDATA[networking]]></category><category><![CDATA[calling]]></category><category><![CDATA[5G]]></category><category><![CDATA[2g]]></category><category><![CDATA[4g]]></category><category><![CDATA[WebRTC]]></category><category><![CDATA[internet]]></category><category><![CDATA[Signaling ]]></category><dc:creator><![CDATA[Vikas Kumar]]></dc:creator><pubDate>Fri, 11 Jul 2025 18:30:00 GMT</pubDate><enclosure url="https://cdn.hashnode.com/res/hashnode/image/upload/v1759210524355/32993107-ff45-4ff4-8374-54bd63ac96a3.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2 id="heading-what-is-ss7">What is SS7?</h2>
<p><strong>Signalling System No. 7</strong>, or simply <strong>SS7</strong>, is a worldwide telecommunications protocol for managing the routing of phone calls, SMS messages, and other services between a network of interconnected signalling points. SS7 facilitates quick communication between various network elements to implement efficient call setup and routing and call termination.</p>
<p>Although it was standardised as early as <strong>1993</strong>, SS7 still remains a crucial back bone for telecommunication services around the globe in <strong>2024</strong>, even in the presence of modern networks.</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1759210555354/925b63bb-de71-4a3c-b79d-aeb4274afacc.jpeg" alt class="image--center mx-auto" /></p>
<blockquote>
<p>In simple terms, SS7 is a network of signalling points that functions like the internet for telecommunications. It enables seamless connection and communication of voice calls and text messages across different telecom systems, similar to how the internet connects various devices and services for data exchange.</p>
</blockquote>
<h3 id="heading-but">BUT!</h3>
<p>Telecoms are simply magicians who invisibly orchestrate call routing, SMS deliveries, and worldwide roaming behind the curtain with the magic of SS7. It's interesting that this industry fails to mention how fragile SS7 can be, basically leaving our calls, messages, and even locations unsecured. Let me explain.</p>
<p>Imagine a small circle of trusted friends who never lock up their places. Anyone can walk in and out as they please, and everything would be fine-since it worked for generations- until an outsider, assuming the role of one of their close friends, slips through one of those open doors.</p>
<p>In telecommunications, SS7 works in a similar manner. It enables service providers to exchange information with minimal security barriers for ensuring communication across different networks, hence effective, but due to its open nature, it also has vulnerabilities through which potential attackers can take advantage.</p>
<h2 id="heading-vulnerabilities-of-ss7">Vulnerabilities of SS7</h2>
<p>It might astonish you that anyone with a high school knowledge in signalling can exploit SS7-and he can do it without the consumer's knowledge.</p>
<ol>
<li><p><strong>Intercept Calls</strong>: Like some unwanted guest who would also listen to what is going on, the attacker might intercept already ongoing calls. They can even pass it to their device so they may overhear private conversations.</p>
</li>
<li><p><strong>Location Information Access</strong>: The hacker hears not only a conversation; he can also know where everybody is. Similarly, an attacker can track where someone is by querying the SS7 network so that he could know where somebody is at all times.</p>
</li>
<li><p><strong>Account Hijacking:</strong> If the hacker has gathered enough information, then it can steal one of your friend's identities. Technically, an attacker might hijack a phone number to intercept SMS-based two-factor authentication codes and gain access to online accounts, personal data, etc.</p>
</li>
</ol>
<p>The vulnerability found exposes the critical weaknesses in the SS7 protocol but originates from earlier network infrastructures. This means that the safety of the communication depends on the transformation of the telecommunication technology. Now, which brings us back to the evolution of networks : from 2G to 5G, smarter and safer, at least more interconnected and greater than just the fast downloads or the live videos being streamed.</p>
<h2 id="heading-2g-to-5g-its-not-just-about-faster-cat-videos">2G to 5G — <strong>It’s Not Just About Faster Cat Videos</strong></h2>
<blockquote>
<p>You might be wondering why we’re still talking about 2G or 3G in the age of 5G. The reason is simple: not every country or network has the advanced infrastructure needed to support the latest technology.</p>
</blockquote>
<ul>
<li><p><strong>2G</strong>: The granddaddy of mobile networks. This was to simply make calls and nothing more-just basic calls.</p>
</li>
<li><p><strong>3G</strong>: The Age of Buffering and Dropped Connections and repeatedly asking "Can you hear me now?"</p>
</li>
<li><p><strong>4G</strong>: Fast Internet, streaming video without interruptions, just like YouTube on the go.</p>
</li>
<li><p><strong>5G</strong>: Unlimited possibilities, the future. Smart cities, drive-less cars, robots performing surgeries-the lot. Upgrade from narrow road to a 16-lane superhighway.</p>
</li>
</ul>
<div class="hn-table">
<table>
<thead>
<tr>
<td>Network generation</td><td>Year introduced</td><td>Key technologies</td><td>Encryption standard</td><td>End-to-End encryption</td><td>Security features</td></tr>
</thead>
<tbody>
<tr>
<td>2G</td><td>1991</td><td>GSM, CDMA</td><td>A5/1 (weak), A5/2, A5/3</td><td>No</td><td>Basic encryption of voice and SMS, vulnerable to eavesdropping and attacks.</td></tr>
<tr>
<td>3G</td><td>2001</td><td>UMTS, CDMA2000</td><td>KASUMI, A5/3</td><td>Partial</td><td>Improved encryption, mutual authentication, vulnerable to some attacks.</td></tr>
<tr>
<td>4G</td><td>2009</td><td>LTE, VoLTE</td><td>128/256-bit AES, ZUC</td><td>Supported (VoLTE)</td><td>Stronger encryption, VoLTE, network slicing, enhanced authentication.</td></tr>
<tr>
<td>5G</td><td>2019</td><td>NR (New Radio), VoNR</td><td>256-bit AES, improved protocols</td><td>Supported</td><td>Advanced security architecture, network slicing, AI-based threat detection, stronger encryption, mutual authentication. ****</td></tr>
</tbody>
</table>
</div><h3 id="heading-why-can-we-just-abandon-2g3g">Why can we just abandon 2G/3G?</h3>
<p>The problem is 2G and 3G networks aren’t going away anytime soon. Many regions still depend on them for basic connectivity. They’re like those old, reliable cars people drive in rural areas—outdated, but they get the job done.</p>
<h2 id="heading-why-internet-based-calling-is-better-whatsapp">Why internet-Based calling is better (WhatsApp)?</h2>
<p>SS7 is vulnerable because it was designed in a time when global networks didn’t exist. No one anticipated communication becoming this... <em>global</em>. Then came the internet, which completely redefined global connectivity.</p>
<p>Internet-based calling is much more secure. Apps like WhatsApp are built with encryption at their core. Instead of being like houses with open doors, they function more like private, soundproof booths. Calls and messages stay strictly between you and the person on the other end.</p>
<h3 id="heading-difference-between-traditional-calling-and-internet-based-calling">Difference between Traditional calling and Internet-based calling</h3>
<div class="hn-table">
<table>
<thead>
<tr>
<td><strong>Aspect</strong></td><td><strong>Traditional Calling</strong></td><td><strong>Internet-based Calling (VoIP)</strong></td></tr>
</thead>
<tbody>
<tr>
<td><strong>Technology</strong></td><td>Circuit-switched network, where a dedicated line is established for the duration of the call.</td><td>Packet-switched network, where voice is converted into data packets and sent over the internet.</td></tr>
<tr>
<td><strong>Call Quality</strong></td><td>Typically consistent and reliable, but can be lower in quality due to legacy infrastructure.</td><td>Dependent on internet speed and stability. High-definition (HD) audio quality possible with good connections.</td></tr>
<tr>
<td><strong>Cost</strong></td><td>Charges per minute or per call, especially for long-distance or international calls.</td><td>Often cheaper, especially for long-distance or international calls. Many services offer free calls over the internet.</td></tr>
<tr>
<td><strong>Infrastructure</strong></td><td>Requires dedicated telephone lines and network infrastructure managed by telecom providers.</td><td>Utilises existing internet infrastructure, no need for additional phone lines.</td></tr>
<tr>
<td><strong>Security</strong></td><td>Calls are generally not encrypted, making them vulnerable to various attacks.</td><td>VoIP can support end-to-end encryption, though security depends on the service provider and setup.</td></tr>
<tr>
<td><strong>Mobility</strong></td><td>Limited to the range of the phone network. Calls need to be made through landlines or mobile networks.</td><td>Can be made from anywhere with an internet connection, including Wi-Fi, mobile data, or wired connections.</td></tr>
<tr>
<td><strong>Features</strong></td><td>Basic features like voicemail, call waiting, and caller ID.</td><td>Advanced features like video calling, instant messaging, screen sharing, and file transfer.</td></tr>
<tr>
<td><strong>Latency</strong></td><td>Low latency as a dedicated line is used, though distance and infrastructure can affect this.</td><td>May experience higher latency due to packet routing, but modern VoIP solutions offer low latency with good networks.</td></tr>
<tr>
<td><strong>Reliability</strong></td><td>Highly reliable as dedicated circuits are used. Less prone to internet issues.</td><td>Depends on internet connectivity. Poor internet quality can result in dropped calls or poor call quality.</td></tr>
<tr>
<td><strong>Setup and Maintenance</strong></td><td>Requires landlines, mobile towers, and dedicated hardware managed by telecom companies.</td><td>Easier to set up; only requires an internet connection and a VoIP app or service.</td></tr>
<tr>
<td><strong>Regulation</strong></td><td>Heavily regulated by governments and telecom authorities.</td><td>Less regulated, though governments are starting to impose some regulations on VoIP services.</td></tr>
<tr>
<td><strong>Accessibility</strong></td><td>Available through landlines and mobile networks worldwide.</td><td>Requires internet access, which may not be as available or reliable in remote areas.</td></tr>
<tr>
<td><strong>Scalability</strong></td><td>Expensive and complex to scale due to physical infrastructure.</td><td>Easily scalable with minimal infrastructure costs, especially for businesses.</td></tr>
</tbody>
</table>
</div><h2 id="heading-how-attackers-make-a-ss7-attack">How attackers make a SS7 attack?</h2>
<p>To attack someone, an attacker typically needs their phone number, which is not hard to find anyways. After that they need to get the access of SS7 network which is not legal and not every telecom provider sell it but there are few who does and that is enough.</p>
<p>An attacker can use a Linux system with an SS7 SDK, which is free to download. Once connected to SS7 protocol to attackers can manipulate the network into believing their device is a legitimate MSC/VLR node.</p>
<blockquote>
<p>The <strong>Mobile Switching Center (MSC)</strong> is a critical switching station that manages and directs your phone calls. The <strong>Visitor Location Register (VLR)</strong>, on the other hand, is a temporary database that keeps track of your location while you are connected to the network. Together, these components help facilitate seamless communication and ensure that calls reach the right destination.</p>
</blockquote>
<p>By pretending to be an MSC/VLR, attackers can find out victim’s location and access their <strong>International Mobile Subscriber Identity (IMSI)</strong>, which is like an ID number for the SIM card (You can compare it with your IMEI). With the IMSI, they can redirect calls and messages to their own devices, putting the victim at risk.</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1759210854862/037a1b05-ea7d-4fae-81a5-805478ef7e52.png" alt class="image--center mx-auto" /></p>
<h2 id="heading-story-time">Story Time</h2>
<h3 id="heading-what-happened"><strong>What Happened:</strong></h3>
<p>In 2017 Attackers used the SS7 vulnerability to intercept SMS messages that banks send to their customers as part of two-factor authentication (2FA). Specifically, they targeted customers of several banks in <strong>Germany</strong>.</p>
<ol>
<li><p><strong>Phase 1: Phishing for Bank Credentials</strong></p>
<p> The attackers initially obtained victims' online banking credentials through <strong>phishing attacks</strong>. This is a common tactic where users are tricked into giving away their bank login details via fake emails or websites.</p>
</li>
<li><p><strong>Phase 2: Exploiting SS7 to Hijack SMS</strong></p>
<p> The banks required a second layer of authentication through <strong>one-time passcodes (OTPs)</strong> sent via SMS. To intercept these OTPs, the attackers used SS7 vulnerabilities.</p>
<ul>
<li><p>Using SS7, they <strong>tracked the location of victims' phones</strong> and <strong>rerouted the OTPs</strong> to their own devices without the victims knowing.</p>
</li>
<li><p>This rerouting happens at the core of the mobile network, so it doesn't involve hacking the actual user's phone or SIM card. The attackers simply made the network forward SMS messages to their own devices.</p>
</li>
</ul>
</li>
<li><p><strong>Phase 3: Draining Bank Accounts</strong></p>
<p> With both the victims' <strong>online banking credentials</strong> and <strong>OTP codes</strong>, the attackers were able to log into the victims' bank accounts and initiate money transfers. They then moved the stolen funds into accounts they controlled.</p>
</li>
</ol>
<h3 id="heading-impact"><strong>Impact:</strong></h3>
<p>The attack allowed attackers to drain money from several customers' bank accounts in <strong>Germany</strong>. Since SS7 vulnerabilities affected the entire mobile communication infrastructure, there wasn't much the banks could do at the time to prevent the SMS rerouting from happening.</p>
<h3 id="heading-how-it-was-discovered"><strong>How It Was Discovered:</strong></h3>
<p>The incident came to light when customers noticed suspicious transactions in their accounts and reported them to their banks. An investigation revealed that the attackers had exploited the SS7 network to intercept the 2FA SMS codes.</p>
<h2 id="heading-what-can-we-do">What can we do?</h2>
<p>Just to make it clear, we cannot avoid 100% of SS7 vulnerabilities until we stop using mobile network all together but we can obviously take some precautions.</p>
<ul>
<li><p>Always enable multi-layered authentication for critical accounts.</p>
</li>
<li><p>For your two-factor authentication (2FA), instead of SMS-based 2FA use authenticator apps like Google Authenticator or Microsoft Authenticator.</p>
</li>
<li><p>Try to use only end-to-end encrypted apps for communication.</p>
</li>
<li><p>Use VPNs whenever possible for added privacy.</p>
</li>
<li><p>Switch to 4G or 5G networks when available for improved security features.</p>
</li>
<li><p>Regularly monitor your bank accounts and don’t neglect any unusual activity.</p>
</li>
</ul>
<h2 id="heading-nothing-to-hide-nothing-to-fear-think-again"><strong>“Nothing to Hide, Nothing to Fear”? Think Again!</strong></h2>
<p>The classic argument — "If I’m not doing anything wrong, why should I care?".</p>
<blockquote>
<p><strong><em>Well privacy is not just about hiding, It’s about protection.</em></strong></p>
<p>Here is an analogy — Would you be okay with leaving your front door unlocked just because you have nothing valuable inside? Probably not. It’s the same with privacy. You might not be hiding anything, but that doesn’t mean someone won’t try to exploit your personal information.</p>
</blockquote>
<ul>
<li><p>In <strong>2019</strong>, over <strong>4 billion records</strong> were compromised due to data breaches. That’s more than half the global population!.</p>
</li>
<li><p>Hackers have used SS7 to intercept 2FA codes and empty bank accounts in a matter of minutes.</p>
</li>
</ul>
<p>One thing is certain: accidents and incidents don’t happen regularly, but it’s always better to be prepared than to regret it later.</p>
<h2 id="heading-conclusion">Conclusion</h2>
<p><strong>Signalling System No. 7 (SS7)</strong> has built the foundation of global networking but it’s era has to end at some time. The future is in encrypted communication which lies in the 5G network but it’s gonna take some time, we are not there yet. Till then we can just be cautious and be aware of such vulnerabilities.</p>
<p>So, the next time someone says, “Nothing to hide, nothing to fear,” just remind them: it’s not about secrecy, it’s about security.</p>
]]></content:encoded></item></channel></rss>