Security researchers have identified a new cyberattack method that exploits vulnerabilities in 5G network signaling protocols to downgrade devices from 5G to 4G connections without user awareness. The technique, classified as a bidding down attack, manipulates unprotected signaling messages between user equipment and network infrastructure to force connections to operate at reduced capability levels. The discovery follows similar research from the Singapore University of Technology and Design’s ASSET Research Group, which previously demonstrated a related downgrade attack called Sni5Gect.
The attack specifically targets weaknesses in the control plane signaling of 4G/5G networks. Attackers can transmit malicious AttachReject or TAUReject messages that cause 5G-capable devices to fall back to 4G connectivity. The exploitation occurs during pre-authentication message exchanges, before full security context establishment, allowing adversaries to modify network behavior without detection.
When devices are downgraded from 5G to 4G, they become subject to reduced service quality and security protections. The lower generation networks lack certain security features specifically implemented in 5G architecture, including enhanced encryption protocols and anti-tracking measures. The vulnerability is particularly concerning given recent incidents like the KT Mobile payment system breach in South Korea, which demonstrated how network vulnerabilities can be exploited for financial fraud.
While 5G networks incorporate advanced security capabilities such as public key encryption of subscriber identifiers and network-side detection mechanisms as defined in 3GPP Release 15 and 16 standards, practical implementation challenges persist. These include complexities in cryptographic key management and timing synchronization, which can impact the effectiveness of downgrade attack prevention. Some operators, like Turkcell, are already exploring quantum-safe security measures to further strengthen 5G network protection against emerging threats.
Recent academic research using the MSA dataset has documented examples of bidding down attacks alongside other 5G/4G network intrusions. The dataset serves as a resource for developing and evaluating intrusion detection systems designed to identify such security threats.
The vulnerability highlights an ongoing challenge in mobile network security that spans multiple generations of cellular technology. False base stations, which can facilitate downgrade attacks, have remained a persistent security consideration throughout the evolution of mobile networks. While 5G implementations include enhanced protections against these threats, complete mitigation remains a work in progress, particularly as network operators continue their transition from legacy systems to full 5G deployment.
Sources: arXiv, CableLabs, Black Arrow Cyber Consulting