Iran-linked tracking of US military phones; CrashStealer found

Investigators reported Iran-linked actors used ad metadata and global roaming data to follow U.S. military phones. Researchers also disclosed CrashStealer for macOS and agencies published a CVD blueprint.

Security investigators reported that foreign actors tied to Iran used advertising metadata combined with global cellular roaming records to track and target smartphones issued to U.S. military personnel. The activity focused on devices while personnel traveled or operated outside the United States.

Investigators found the campaign joined metadata from commercial ad networks-such as device identifiers, IP addresses and app activity-with roaming information exchanged between mobile operators during international network handoffs. Correlating those two streams produced travel histories and movement patterns that allowed operators to monitor and single out specific phones.

The tracking reportedly relied on commercially available data feeds rather than direct breaches of operator networks. Military and telecommunications authorities have been notified and are reviewing how roaming data is shared and what protections ad networks apply to accounts linked to official devices.

Separately, security researchers disclosed a macOS information stealer named CrashStealer. Written in C++, the program disguises itself as a system crash reporter, captures files, stored credentials and system details, and exfiltrates that data to attacker-controlled servers. The malware presents native-like dialog boxes that request passwords and mimics expected system behavior to reduce suspicion. Researchers noted devices without current updates or user scrutiny of unexpected prompts are more exposed and recommended verifying system dialogs before entering credentials and watching for unusual network activity.

The Cybersecurity and Infrastructure Security Agency and international partners published a blueprint for building Coordinated Vulnerability Disclosure programs. The guide outlines procedures for receiving and triaging external bug reports, setting disclosure timelines, creating legal safe harbors for researchers, and working with outside security experts. It includes model policies for sensitive reports, sample communication templates, and recommendations for technical intake systems to avoid duplicate work.

Advertising technology platforms routinely collect device and usage signals to deliver ads, and mobile networks exchange roaming information to authenticate devices that move between operators. When those two information streams are combined, they can reveal location and identity details without direct access to subscriber records. Coordinated Vulnerability Disclosure programs formalize how external researchers report flaws, typically including commitments on response timelines and protections for good-faith reporting.

Articles by this author