Cathal Mc Daid Profile picture
Mar 29 6 tweets 4 min read
🧵A good recent example of #Ukraine contesting the Mobile Network / InfoSec battlespace.

Multiple #SIMBox seizures as part of an "enemy bot farm" network were announced yesterday by the Security Service of Ukraine. 1/6
ssu.gov.ua/novyny/z-pocha…
Technically this is a much bigger setup that the #SIMBox relay discovery from 2 weeks ago, (see my previous thread) which is not surprising as these are more traditional ‘bot farms’ used for signups for social media 2/6
According to the #SBU, the 5 enemy bot farms in the network used social media (including some banned in Ukraine) to “spread disinformation about a full-scale Russian invasion of our state and spread distorted news from the front”.

This network used 100,000 fake accounts 3/6
On the telecom side, visually this comprises of what looks like Shenzhen Yundatong Technology's Eyondalink 64 SIM GSM Modems.

Presumably these would connect to a server to register and then receive SMSs as part of the fake account setup process 4/6
aliexpress.com/i/400098376274… ImageImage
Ukraine has been identifying and cracking down on these for years, including recently before the war – here is a somewhat smaller one from February 9th with similar equipment.

But the one announced yesterday is a big one 5/6
vice.com/en/article/4aw…
For a timeline of other developments in the Ukrainian Mobile Network space, that have impacted the war see our latest blog 6/6

blog.adaptivemobile.com/the-mobile-net… Image

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Cathal Mc Daid

Cathal Mc Daid Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @mcdaidc

Mar 15
1/5 Another significant capture in #Ukraine. Reported discovery today of a #SIMBox being used to relay Voice calls & SMS and other info to Russian forces (including top leadership of Russian army) & other individuals in #Ukraine. I will explain what this is and how it works.
2/5
First the system is comprised of 3 main parts,
1) the SIM Box server - in this case a Hypertone SMB-128 . This handles the control of up to 128 SIM Cards, cycles them when detected etc , and co-ordinates interaction with the #GSM Gateways
hybertone.com/en/pro_detail.… Image
3/5 Next the GSM Gateways, there are two Hypertone types being used here:
- There are 3x GoIP 8 - VoIP Gateway for 8 Channels being used,
- along with 1x GoIP-4 4 SIM VoIP GSM Gateway.
Both can be used for SMS or Voice ImageImage
Read 7 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(