Iran-linked actors track US troops using ad and roaming data

Advertising metadata and cellular roaming signals tied to Iran were used to monitor U.S. military phones. Researchers also found CrashStealer macOS malware and CISA published a CVD blueprint.

Investigators found that actors linked to Iran used advertising-technology metadata and global cellular roaming information to track smartphones carried by U.S. military personnel. The activity involved signals exchanged in commercial systems rather than direct access to carrier networks.

The technique relied on device identifiers and location-related metadata embedded in ad networks and on roaming protocol data that records when and where devices connect to foreign cellular networks. By correlating identifiers from advertising exchanges with roaming events, the actors built movement profiles of individual devices.

Researchers characterized the operation as aggregation of commercial signals. They collected advertising exchange identifiers, matched those identifiers to roaming records that show network connections abroad, and then linked those combined signals to the phones of service members.

Separately, security teams uncovered CrashStealer, a new macOS information stealer written in C++. The malware poses as a native crash reporting app to gain user trust and bypass some routine checks. Once installed, CrashStealer gathers credentials, system information and other sensitive data from infected machines.

CrashStealer uses fake system prompts and imitates native macOS behavior to capture or request inputs from users. Samples observed by researchers are engineered to run quietly, package collected data and send it to remote servers under attacker control.

CISA and international partners released a joint blueprint for Coordinated Vulnerability Disclosure and bug bounty programs. The guide provides steps for receiving and triaging external vulnerability reports, for creating legal safe harbors for security researchers, and for setting up collaboration between private companies and government agencies.

The blueprint is aimed at organizations that want formal procedures for handling external finders and reducing the chance of uncoordinated disclosures. It includes practical recommendations on report intake, prioritization and legal protections for researchers who follow disclosed rules.

Security teams and network operators are continuing to investigate the scale of the tracking operations and to map the extent of CrashStealer infections. Companies and agencies are reviewing the CVD guidance to decide how to update their disclosure and bug bounty policies.

Articles by this author