SMS Blaster Detection in the Field: Lessons from the Yettel Serbia Incident

In late 2025, Serbian law enforcement arrested two Chinese nationals operating an improvised IMSI catcher from a moving vehicle in Belgrade. The device impersonated legitimate base stations, capturing nearby devices, downgrading them to unsecured 2G, and delivering smishing messages to harvest payment card data, all without a single byte passing through the operator's network.

 

The investigation concluded with arrests on 10 December 2025, confirming what network analysis had indicated: a mobile rogue base station that targeted Belgrade residents for roughly two weeks.

 

This case study examines the threat, how it was detected, and how operators can build systematic capability to identify and respond to SMS Blaster attacks before they escalate.

Published:

  • Telecom Fraud
  • A2P SMS
  • SMS Blaster

The Threat: What SMS Blasters Do and Why They Are Hard to Stop

An SMS blaster is a portable false base station. Its attack exploits a fundamental asymmetry in mobile security: 3G/4G/5G networks have the mandatory mutual authentication mechanism to validate both the network and device, but legacy 2G has this mechanism as unilateral, not mutual. Attackers exploit this gap in four steps:

  1. Simulate a legitimate 4G network to attract nearby devices
  2. Use RRC (Radio Resource Control) redirection to downgrade connections to unsecured 2G
  3. Inject fraudulent SMS messages directly: no SMSC, no billing record, no firewall event
  4. Release devices back to the legitimate network

The result is an attack that is invisible to every conventional fraud control an MNO operates.

The Serbia Incident

A photo with an opened trunk of a black car. SMS blaster equipment is visible in the trunk, a power unit, SIMbox, IMSI catcher, etc.). This photo was initially published on Nova.rs and belongs to Ministry of Internal Affairs, Serbia.
Source: Nova.rs, Ministry of Internal Affairs, Serbia

Yettel Serbia detected anomalous signaling behavior in late August 2025. The investigation revealed a mobile rogue base station campaign operating across Belgrade.

Location Belgrade, Serbia
Attack period Q4, 2025
Method Improvised IMSI catcher installed in a moving vehicle, impersonating legitimate base stations
Smishing content Malware link attempting to collect banking information (data about payment cards)
Arrests 10 December 2025: two Chinese nationals arrested following several months of investigation
Law enforcement Serbian Police High-Tech Crime Unit, in cooperation with telecom operators

How the Attack Was Detected

SMS Blasters leave no trace in CDRs, billing records, or SMS logs. They leave traces elsewhere: in radio network signaling, at the cell reselection layer. Detection in the Yettel case relied on two data sources working together.

1. Radio Network Signaling Analysis (A-Interface, MSC - BSC)

A rogue base station cannot perfectly impersonate a legitimate one. It broadcasts invalid location area codes (LAC) and parameters. Once the affected devices are released back to the legitimate network, radio network signaling increases.

These signals are not obvious in isolation. Identifying them requires a detailed low-level analysis across multiple signaling streams and close coordination between Information Security, Core Network, and RAN teams.

2. Subscriber Complaints

Affected subscribers reporting unsolicited messages provided the initial trigger and confirmed an active campaign. Complaints alone cannot identify an SMS Blaster (they could reflect many fraud types), but combined with signaling anomalies, they anchor the analysis.

What the Incident Reveals About Detection Readiness

Detection was reactive and manual

Yettel's Analytical Fraud Management System had access to the needed signaling data, but detection relied primarily on ad-hoc analysis. Because the SMS Blaster attack is a relatively new, emerging fraud type, automated scenarios for it were not configured in advance. Therefore, the window between attack onset and detection was longer than it needed to be, and resolution depended on the right people asking the right questions at the right time.

Cross-team collaboration was essential

No single team held all the pieces: Fraud had subscriber complaints, Core Network had signaling data, and RAN had the context to interpret base station behavior. Yettel's Fraud, Information Security, Core Network, and RAN teams worked in concert to identify and confirm the attack. Operators without established collaboration paths between these functions are practically blind to SMS Blaster attacks.

Resolution requires law enforcement and data

An SMS Blaster cannot be blocked by a network configuration change. The device is physical, mobile, and operates entirely outside network infrastructure. Resolution means finding and stopping its operator, which requires mobile positioning data. A key capability to develop was combining fraud detection with E-SMLC positioning to identify unknown base stations and give law enforcement location estimates derived from RSRP/RSRQ measurements.

Automated detection scenarios must follow

As a direct consequence of the incident, a comprehensive set of automated detection scenarios was implemented, including:

  • Detection of invalid radio signaling parameters
  • Monitoring of 2G Cell downgrade patterns
  • ML model evaluation of mobile detach and re-attach patterns

The case demonstrated that rare-but-high-impact fraud types require pre-configured automated detection. Waiting for an attack before developing the capability is too late.

What MNOs Should Do Differently

The Yettel incident points to a clear set of gaps that systematic capability can close.

Move from ad-hoc to automated

Detection based on analyst intuition is valuable but slow. The signaling anomalies identified manually (invalid radio network parameters, bursts of subscriber detach and re-attach volume spikes, and changes in the 2G Cell downgrade patterns) can all be modelled as automated scenarios running continuously against live signaling feeds. ML models can evaluate cell reselection patterns in near-real time and surface events for human review, rather than waiting for a complaint to trigger investigation.

Instrument the right data sources

Radio network signaling, including A-Interface (2G/3G), 3G Iu-CS, LTE S1, and 5G NG, is the only layer where SMS Blaster activity is visible. Operators not systematically ingesting and analyzing this data cannot detect these attacks. SMS firewalls and CDR-based rules offer zero visibility into this threat category.

Build the full response chain, not just detection

Detection without subscriber notification, case management, and positioning support for law enforcement is incomplete. The time between attack and harm is short, so automated subscriber notification and optional data access restriction are part of the response, not add-ons.

Connect detection to positioning

Law enforcement can act when given precise data. Location estimation lets operators provide actionable positioning data to authorities. This is the difference between reporting an anomaly and enabling an arrest.

Heksagon SMS Blaster Detection and Protection

Process diagram illustrating Heksagon's Convergent Fraud Analytics ingesting multi-generational radio network signaling (A-Interface, 3G Iu-CS, LTE S1, and 5G NG) to run SMS Blaster scenarios and detect handover layer anomalies.

The detection methodology that proved effective in the Yettel investigation, signaling anomaly analysis, multi-source correlation, and positioning support, is exactly what Heksagon's Convergent Fraud Analytics platform delivers, in automated, continuous form.

The platform ingests A-Interface (2G/3G), 3G Iu-CS, LTE S1, and 5G NG signaling data via mirror, proxy, or near-real-time feed from existing monitoring infrastructure. Detection scenarios correlate multiple streams using AI/ML models, reducing false positives and raising detection confidence beyond what any single signal can achieve. As GSMA recommends, correlating signals across multiple detection layers is key to minimizing false-positive rates. This principle is at the core of Heksagon's approach.

SMS Blaster Detection and Protection runs within the same Convergent Fraud Analytics platform used for SIMBOX prevention, interconnect fraud management, and other analytical fraud scenarios. Operators already on the platform can activate it through the same data infrastructure and analyst interface, with no separate system required. For new customers, the SMS Blaster solution can be packaged as a lightweight module for faster implementation.

Heksagon Capability

Effect

Radio network signaling analysis

Continuous monitoring of A-Interface, Iu-CS, LTE-S1, and 5G NG data; automated detection of cell reselection anomalies and invalid location parameters

Multi-stream AI/ML correlation

Cross-stream scenario processing to raise detection confidence and reduce false-positive noise

Subscriber impact identification

Automatic identification of affected subscribers at point of detection

Proactive subscriber notification

Warning notifications dispatched before subscribers act on malicious messages

Data access restriction

Optional temporary restriction of mobile-data access via provisioning platform API

E-CID-based location estimation

Sequenced processing of RSRP/RSRQ data from the E-SMLC module to estimate rogue device location for law enforcement

Case management

Complete signaling history, subscriber impact lists, and geographic data packaged for analyst review or law enforcement reporting

Conclusion

The Belgrade case is instructive precisely because detection succeeded, but only through a combination of a proactive solution, cross-team collaboration, external peer knowledge, and a willingness to look in the right data layer. Those conditions might not reliably exist next time.

The attack technique is neither new nor rare. SMS Blaster devices are commercially available online, simple to deploy, and effective against every conventional fraud control an MNO runs. Your network will be targeted sooner or later. The question is whether you will know when it happens. To stay ahead of this evasive fraud scheme, contact Heksagon.