Researchers from Singapore University of Technology and Design’s ASSET Research Group have developed a new cyberattack method called Sni5Gect that can downgrade 5G phones to 4G networks without requiring a rogue base station, marking a significant advancement in mobile network security threats.
The attack, whose name stands for “Sniffing 5G Inject,” works by exploiting vulnerabilities during the communication setup between a 5G phone and the base station. It passively monitors unencrypted messages during the user equipment (UE) attach procedure and injects malicious messages over-the-air to the target device. The method is particularly concerning as it bypasses many of the enhanced security features implemented in 5G networks.
Unlike traditional attacks that rely on false base stations, Sni5Gect functions as a third-party observer that monitors and injects messages into the communication stream. “SNI5GECT acts as a third-party in the communication, silently sniffs messages, and tracks the protocol state by decoding the sniffed messages during the UE attach procedure,” the researchers explain.
The technique has been successfully tested on multiple flagship devices from manufacturers including Samsung, Google, Huawei, and OnePlus. When a device is downgraded from 5G to 4G, it becomes subject to less secure network protocols, potentially exposing users to various security risks. The attack can also cause the phone’s modem to crash, resulting in denial of service.
Sni5Gect builds upon previously discovered vulnerabilities in 5G modem firmware from major chipmakers MediaTek and Qualcomm, known collectively as 5Ghoul, which were identified in late 2023. The attack exploits the fact that certain critical messages exchanged during initial connection setup remain unencrypted, despite increased investment in mobile network security by major telecommunications providers.
While 5G standards have implemented security measures like public key encryption of subscriber identifiers to prevent false base station attacks, these protections do not fully address attacks like Sni5Gect that operate without the need for rogue infrastructure. The vulnerability highlights the ongoing challenges in securing mobile networks as they evolve, even as organizations like the GSMA work to enhance security standards for mobile communications.
Sources: The Hacker News, TechRadar, Western Illinois University, CableLabs