ROAMING_BEACON
RO EN
OPEN ANALYSIS // INTEL_REP

Pocket Beacon · How Phones are Hunted in Warzone Operations

During the recent conflict in the Middle East, mobile networks were flooded with silent location queries. Without compromising devices directly, adversaries leveraged legacy roaming protocols and commercial advertising databases to track the movements of US personnel. This is the anatomy of two invisible pathways turning ordinary smartphones into kinetic targets.

Note: Analysis based on data from the Mobile Surveillance Monitor project, Citizen Lab, and official reports submitted to the US Congress. Does not reflect classified materials.
SS7
Hundreds of signaling queries (pings) sent via international roaming agreements.
0-DAY
Precision geolocations processed at the network layer without installing malicious payloads.
AD-ID
Advertising profiles acquired from open commercial channels to reveal transient military nodes.
GRID
Physical targeting resolution refined to building level, verifying device groupings in real-time.
PATHWAY 01 // CORE TELECOM VULNERABILITY

Exploiting Implicit Trust in Global Telecom Routing

SS7 (Signaling System No. 7) is the legacy global routing backbone established in the 1970s to route calls and text messages between different carrier networks. The architecture was built on the core assumption that any participant connected to the signaling core is inherently trusted.

This structural trust is highly weaponizable. A foreign state-linked operator can issue legitimate-looking signaling messages (such as Provide Subscriber Information) to query where a roaming phone is currently located. The device's home network blindly handles the routing request, returning the ID of the local cell tower the targeted user is connected to, exposing real-time locations without user interaction.

Use the emulator on the right to witness how an SS7 ping request crosses networks to track a targeted device.

SS7 Query Routing Simulator
SYSTEM_READY
// Terminal initialized. Ready for routing request emulation.
08:14:02
WeatherRadar
5F02B8-F82B
26.2415, 50.5902
Bahrain Navy Base
08:15:10
FitExTrack
1A940C-002E
26.2223, 50.5841
Manama Crowne Plaza
08:19:44
NewsBrief
8D04B3-D72B
36.2491, 44.0201
Erbil Military Outpost
08:21:02
FlashlightX
5F02B8-F82B
26.2418, 50.5905
Bahrain Navy Base
08:25:30
WeatherRadar
1A940C-002E
26.2224, 50.5843
Manama Crowne Plaza
08:30:12
FitExTrack
5F02B8-F82B
26.2414, 50.5901
Bahrain Navy Base
08:34:55
NewsBrief
1A940C-002E
26.2225, 50.5842
Manama Crowne Plaza
08:41:03
LocalGuides
9C02B9-A21F
36.2495, 44.0204
Erbil Military Outpost
08:44:22
WeatherRadar
8D04B3-D72B
36.2492, 44.0200
Erbil Military Outpost
PATHWAY 02 // COMMERCIAL ADVERTISING TRAIL

The Digital Exhaust: Converting Commercial Data to Tactical Intelligence

Beyond carrier networks, devices constantly leak metadata via commercial apps (weather, utilities, fitness, games). These apps report precise GPS coordinates coupled with the device's unique Advertising ID (Ad-ID, such as MAID or IDFA) to request localized ads.

Data brokers continuously aggregate these location footprints into massive commercial databases. Threat actors purchase licensing access to ad-intelligence software. By building simple behavioral filters (e.g., 'locate devices tracking from Navy base assets to hotels hosting contractors'), adversaries reconstruct operational routines and pinpoint high-value personnel.

Filter the advertising telemetry database on the left to track clusters at the naval base or the hotel.

TEMPORAL CORRELATION // ALIGNMENT

Chronology of Coincidence: Cyber Signals and Kinetic Impact

2026.02.20 CYBER SIGNAL

Surge of Blocked SS7 Pings in Gulf Networks

Telemetry logs from the Mobile Surveillance Monitor project recorded a heavy surge of signaling locate attempts sourced from threat actors. The queries specifically target roaming numbers active in the vicinity of allied facilities.

2026.02.25 CYBER SIGNAL

Ad-ID Database Exploitation Detected in Iraqi Kurdistan

US defense officials noted suspicious queries on commercial location databases gathering device tracks inside Erbil, specifically targeting Wi-Fi networks utilized near contractor lodging.

2026.03.02 KINETIC IMPACT

Kinetic Strike on Manama Crowne Plaza Hotel

A rocket strike hit the Bahrain hotel housing US naval contractors. The precision strike followed a pattern where high densities of military personnel Ad-ID coordinate tracks had converged on the building.

2026.03.12 KINETIC IMPACT

Drone Strike on Kurdish Military Base in Erbil

A military base north of Erbil was hit by armed drones. Centcom subsequently confirmed persistent intelligence warnings highlighting adversary exploitation of commercial geolocations in the sector.

2026.04.10 CYBER SIGNAL

Centcom Submits Threat Briefings to Congress

In a formal briefing to lawmakers, US Central Command warned that adversaries are actively utilizing commercial location data feeds to target and monitor troops in theater.

Documentation and Bibliographic Sources