SMS Blaster Detection in the Field: Lessons from the Yettel Serbia Incident
In late 2025, Serbian law enforcement arrested two Chinese nationals operating an improvised IMSI catcher from a moving vehicle in Belgrade. The device impersonated legitimate base stations, capturing nearby devices, downgrading them to unsecured 2G, and delivering smishing messages to harvest payment card data, all without a single byte passing through the operator's network.
The investigation concluded with arrests on 10 December 2025, confirming what network analysis had indicated: a mobile rogue base station that targeted Belgrade residents for roughly two weeks.
This case study examines the threat, how it was detected, and how operators can build systematic capability to identify and respond to SMS Blaster attacks before they escalate.
Published:
The Threat: What SMS Blasters Do and Why They Are Hard to Stop
An SMS blaster is a portable false base station. Its attack exploits a fundamental asymmetry in mobile security: 3G/4G/5G networks have the mandatory mutual authentication mechanism to validate both the network and device, but legacy 2G has this mechanism as unilateral, not mutual. Attackers exploit this gap in four steps:
- Simulate a legitimate 4G network to attract nearby devices
- Use RRC (Radio Resource Control) redirection to downgrade connections to unsecured 2G
- Inject fraudulent SMS messages directly: no SMSC, no billing record, no firewall event
- Release devices back to the legitimate network
The result is an attack that is invisible to every conventional fraud control an MNO operates.
The Serbia Incident
Yettel Serbia detected anomalous signaling behavior in late August 2025. The investigation revealed a mobile rogue base station campaign operating across Belgrade.
| Location | Belgrade, Serbia |
| Attack period | Q4, 2025 |
| Method | Improvised IMSI catcher installed in a moving vehicle, impersonating legitimate base stations |
| Smishing content | Malware link attempting to collect banking information (data about payment cards) |
| Arrests | 10 December 2025: two Chinese nationals arrested following several months of investigation |
| Law enforcement | Serbian Police High-Tech Crime Unit, in cooperation with telecom operators |
How the Attack Was Detected
SMS Blasters leave no trace in CDRs, billing records, or SMS logs. They leave traces elsewhere: in radio network signaling, at the cell reselection layer. Detection in the Yettel case relied on two data sources working together.
1. Radio Network Signaling Analysis (A-Interface, MSC - BSC)
A rogue base station cannot perfectly impersonate a legitimate one. It broadcasts invalid location area codes (LAC) and parameters. Once the affected devices are released back to the legitimate network, radio network signaling increases.
These signals are not obvious in isolation. Identifying them requires a detailed low-level analysis across multiple signaling streams and close coordination between Information Security, Core Network, and RAN teams.
2. Subscriber Complaints
Affected subscribers reporting unsolicited messages provided the initial trigger and confirmed an active campaign. Complaints alone cannot identify an SMS Blaster (they could reflect many fraud types), but combined with signaling anomalies, they anchor the analysis.
What the Incident Reveals About Detection Readiness
Detection was reactive and manual
Yettel's Analytical Fraud Management System had access to the needed signaling data, but detection relied primarily on ad-hoc analysis. Because the SMS Blaster attack is a relatively new, emerging fraud type, automated scenarios for it were not configured in advance. Therefore, the window between attack onset and detection was longer than it needed to be, and resolution depended on the right people asking the right questions at the right time.
Cross-team collaboration was essential
No single team held all the pieces: Fraud had subscriber complaints, Core Network had signaling data, and RAN had the context to interpret base station behavior. Yettel's Fraud, Information Security, Core Network, and RAN teams worked in concert to identify and confirm the attack. Operators without established collaboration paths between these functions are practically blind to SMS Blaster attacks.
Resolution requires law enforcement and data
An SMS Blaster cannot be blocked by a network configuration change. The device is physical, mobile, and operates entirely outside network infrastructure. Resolution means finding and stopping its operator, which requires mobile positioning data. A key capability to develop was combining fraud detection with E-SMLC positioning to identify unknown base stations and give law enforcement location estimates derived from RSRP/RSRQ measurements.
Automated detection scenarios must follow
As a direct consequence of the incident, a comprehensive set of automated detection scenarios was implemented, including:
- Detection of invalid radio signaling parameters
- Monitoring of 2G Cell downgrade patterns
- ML model evaluation of mobile detach and re-attach patterns
The case demonstrated that rare-but-high-impact fraud types require pre-configured automated detection. Waiting for an attack before developing the capability is too late.
What MNOs Should Do Differently
The Yettel incident points to a clear set of gaps that systematic capability can close.
Move from ad-hoc to automated
Detection based on analyst intuition is valuable but slow. The signaling anomalies identified manually (invalid radio network parameters, bursts of subscriber detach and re-attach volume spikes, and changes in the 2G Cell downgrade patterns) can all be modelled as automated scenarios running continuously against live signaling feeds. ML models can evaluate cell reselection patterns in near-real time and surface events for human review, rather than waiting for a complaint to trigger investigation.
Instrument the right data sources
Radio network signaling, including A-Interface (2G/3G), 3G Iu-CS, LTE S1, and 5G NG, is the only layer where SMS Blaster activity is visible. Operators not systematically ingesting and analyzing this data cannot detect these attacks. SMS firewalls and CDR-based rules offer zero visibility into this threat category.
Build the full response chain, not just detection
Detection without subscriber notification, case management, and positioning support for law enforcement is incomplete. The time between attack and harm is short, so automated subscriber notification and optional data access restriction are part of the response, not add-ons.
Connect detection to positioning
Law enforcement can act when given precise data. Location estimation lets operators provide actionable positioning data to authorities. This is the difference between reporting an anomaly and enabling an arrest.
Heksagon SMS Blaster Detection and Protection
The detection methodology that proved effective in the Yettel investigation, signaling anomaly analysis, multi-source correlation, and positioning support, is exactly what Heksagon's Convergent Fraud Analytics platform delivers, in automated, continuous form.
The platform ingests A-Interface (2G/3G), 3G Iu-CS, LTE S1, and 5G NG signaling data via mirror, proxy, or near-real-time feed from existing monitoring infrastructure. Detection scenarios correlate multiple streams using AI/ML models, reducing false positives and raising detection confidence beyond what any single signal can achieve. As GSMA recommends, correlating signals across multiple detection layers is key to minimizing false-positive rates. This principle is at the core of Heksagon's approach.
SMS Blaster Detection and Protection runs within the same Convergent Fraud Analytics platform used for SIMBOX prevention, interconnect fraud management, and other analytical fraud scenarios. Operators already on the platform can activate it through the same data infrastructure and analyst interface, with no separate system required. For new customers, the SMS Blaster solution can be packaged as a lightweight module for faster implementation.
|
Heksagon Capability |
Effect |
|
Radio network signaling analysis |
Continuous monitoring of A-Interface, Iu-CS, LTE-S1, and 5G NG data; automated detection of cell reselection anomalies and invalid location parameters |
|
Multi-stream AI/ML correlation |
Cross-stream scenario processing to raise detection confidence and reduce false-positive noise |
|
Subscriber impact identification |
Automatic identification of affected subscribers at point of detection |
|
Proactive subscriber notification |
Warning notifications dispatched before subscribers act on malicious messages |
|
Data access restriction |
Optional temporary restriction of mobile-data access via provisioning platform API |
|
E-CID-based location estimation |
Sequenced processing of RSRP/RSRQ data from the E-SMLC module to estimate rogue device location for law enforcement |
|
Case management |
Complete signaling history, subscriber impact lists, and geographic data packaged for analyst review or law enforcement reporting |
Conclusion
The Belgrade case is instructive precisely because detection succeeded, but only through a combination of a proactive solution, cross-team collaboration, external peer knowledge, and a willingness to look in the right data layer. Those conditions might not reliably exist next time.
The attack technique is neither new nor rare. SMS Blaster devices are commercially available online, simple to deploy, and effective against every conventional fraud control an MNO runs. Your network will be targeted sooner or later. The question is whether you will know when it happens. To stay ahead of this evasive fraud scheme, contact Heksagon.
Related Reading:
-
SMS Blaster Attacks: Why Rogue Base Stations Are a Growing Telecom Fraud Problem
Find out more about the attack mechanics behind SMS Blasters and learn how the detection and defense strategies actually work.
-
What Is Telecom Fraud? A Complete Guide for MNOs
See how the SMS Blaster fraud scheme fits alongside other, more traditional fraud types.