>>> Research Division
Research
Intelligence
Protocol-level vulnerability analysis across 3GPP signaling stacks, core network interfaces, and radio access layers. Every vector catalogued. Field research reproduced.
Per-protocol vulnerability catalogues, animated call-flow procedures, and attack taxonomies across 2G, 3G, 4G, and 5G SBA.
Seminal conference talks, academic papers, and CVE exploit chains reproduced and verified in the TelcoSec ProLabs range.
GSM Air Interface
2GUm air interface — IMSI catchers, A5/0 cipher downgrade, COMP128v1 SIM cloning, unauthenticated backhaul.
SS7 / MAP
2G · 3GLegacy TDM signaling — cell-level geolocation, call interception, SMS hijack via unauthenticated MAP operations.
CAMEL / CAP
2G · 3GIntelligent Network control — prepaid billing bypass, call redirect, VLR manipulation via CAP state manipulation.
Diameter
4G · IMSS6a/Cx/Gx interfaces — auth vector theft, subscriber tracking, QoS manipulation, HSS subscriber profile extraction.
SIP / VoLTE
4G · VoLTEVoLTE signaling — REGISTER hijacking, SDP media redirect, INVITE flood amplification, CLI spoofing.
GTP-C / GTP-U
3G · 4G · 5GGPRS Tunneling Protocol — Create Session spoofing, TEID injection, IMSI enumeration, data plane hijacking.
SIGTRAN / SCTP
3G · 4GSS7-over-IP transport — ASP registration abuse, OPC spoofing, SCTP ABORT flooding, multi-homing disruption.
4G EPC Core
4G LTEMME, SGW, PGW architecture — S1-AP abuse, bearer session hijacking, tracking area update spoofing.
IMS Core
4G · VoLTEHSS, P/I/S-CSCF architecture — VoLTE interception, registration storms, emergency service bypass.
5G SBA
5G NRService-Based Architecture — NF service spoofing, network slicing bypass, SBI HTTP/2 JSON injection, NRF poison.
RAN Architecture
4G · 5GRadio Access Network — X2/Xn handover manipulation, F1-AP exposure, NGAP attacks, rogue gNodeB broadcast.
Featured Field Reproductions
Independent validation and lab harness reproduction of premier telecom security research
5G SUCI De-Anonymization via Null-Scheme & Side-Channel
By Benoit Michau & Altaf Shaik
Rogue gNodeB forces Scheme 0 or profiles SIDF response latencies to recover raw subscriber SUPI over 5G SA air interfaces.
Ghost SIM Attack: Cellular Authentication Policy Exploit
By Pedro Cabrera & Miguel Gallego
Exploiting weak SIM authentication policies and SDR signal recording in 4G/5G networks to clone virtual subscriber sessions.
Simjacker: Exploiting S@T Browser via Binary OTA SMS
By Cathal McDaid (AdaptiveMobile)
Unauthenticated binary SMS messages targeted at port 0x0208 trigger STK bytecode execution to silently leak cell-tower location.
GTP-U Data Plane Injection & Over-Billing Hijacking
By Gabriel K. H. & Shinjo Park
Predicting unauthenticated 32-bit TEIDs on core UPF interfaces to inject spoofed DNS responses and impersonate victim IP packets.
Baseband Over-The-Air Remote Code Execution (Shannon LTE)
By Xuefeng Li & Dongdong She
Heap buffer overflow in Shannon modem RRC ASN.1 parser triggered by crafted over-the-air radio frames from a rogue base station.
SS7 Location Tracking & Interception via SRI & PSI
By Tobias Engel & Karsten Nohl
Direct MAP SRI-SM and ProvideSubscriberInfo queries across international interconnects to track subscriber cells and intercept calls.