Can a Mobile Phone Be Bugged Without Spyware?

Understanding SS7 and Network-Based Surveillance

Claude Khoury, Chief Operating Officer, NSI Global

ORIGINAL PUBLICATION: 14 July 2018  REVISION COMPLETED: 17 September 2026

A mobile phone can be monitored without spyware being installed on the handset, but the mechanism and likely evidence differ from a device compromise. Mobile-network signalling abuse, a rogue base station, subscriber-account fraud, compromised cloud accounts and spyware are separate attack paths. Each exposes different information, requires different access and calls for a different investigation.

That distinction matters. A person who assumes every suspicious event is spyware may alter or reset a device and destroy useful evidence. A business that assumes encryption solves every mobile risk may overlook account recovery, metadata, device compromise or telecommunications exposure. The correct response begins with a threat model, not a single product or test.

Mobile Interception Requires the Right Threat Model

The word bugged is often used to describe several technically different events. It may mean that calls or messages were intercepted in transit, that a phone was connected to a rogue base station, that a mobile number was transferred fraudulently, that an online account was accessed, or that spyware was operating on the device.

Those possibilities should not be treated as interchangeable. They differ in capability, persistence, cost, detectability and evidential footprint. The most useful first question is therefore not simply whether the phone is hacked. It is what information or function appears to have been exposed and which pathway could realistically explain it.

For example, approximate location tracking through telecommunications signalling does not establish that an attacker can operate the device camera. Interception of an SMS authentication code does not prove access to an encrypted messaging conversation. A stolen cloud session may expose backed-up data even when the handset itself is technically sound.

NSI Global and the 2015 60 Minutes Investigation

In 2015, NSI Global provided consultancy to journalist Ross Coulthart for a 60 Minutes investigation into weaknesses in the global mobile telecommunications system. In the controlled demonstration, security researchers with authorised SS7 access intercepted and recorded mobile calls, intercepted SMS messages and tracked Senator Nick Xenophon’s mobile movements across international locations to the serving cell area. The significance was that these capabilities were exercised through telecommunications signalling rather than by first installing spyware on the target handset.

The investigation also examined rogue mobile infrastructure and IMSI-catcher activity. These are related mobile-surveillance risks but they are not the same technique: SS7 attacks abuse inter-carrier signalling, while an IMSI catcher impersonates legitimate radio infrastructure in the target’s vicinity. Keeping those pathways separate is important because the evidence, detection methods and defensive controls differ.

Watch the 60 Minutes Australia investigation: Bugged, Tracked, Hacked (2015)

That historical demonstration should not be read as proof that every mobile phone is always subject to complete remote control. Mobile networks, interconnect filtering and signalling-firewall controls have evolved since 2015, and exposure varies by operator, roaming path and network configuration. However, the underlying classes of SS7 abuse remain relevant: current telecommunications-security research still documents location tracking, call interception, SMS interception, denial of service and fraud where signalling protections can be bypassed or are insufficient.

How Mobile Network Signalling Can Be Abused

Signalling System Number 7, generally called SS7, is a family of protocols used by telecommunications networks to exchange information needed for services such as call routing, text messaging, roaming and subscriber location. It was designed for an environment in which participating network entities were broadly trusted.

That trust model created opportunities for an actor with suitable network access to send inappropriate signalling requests or impersonate network functions. The United States National Institute of Standards and Technology describes device-location tracking through SS7 as a carrier-interoperability threat. MITRE ATT and CK likewise identifies impersonation of SS7 nodes as a technique that may reveal the geographical cell area or nearest cell tower associated with a device.

Modern mobile systems have introduced newer protocols and stronger security controls. Fourth-generation networks commonly use Diameter-based signalling, while fifth-generation architecture adds further protections. However, mobile communications still depend on roaming, interconnection and compatibility across several generations of technology. A risk assessment must therefore consider the actual operator, countries, roaming arrangements and services involved rather than treating SS7 as either universally dominant or completely obsolete.

Defence against signalling abuse largely sits with telecommunications providers. Relevant controls include signalling firewalls, interconnection filtering, validation of request origin, anomaly detection and information sharing between operators. A subscriber cannot configure these network controls from the handset.

What Signalling Abuse May Enable

Where an attacker has suitable interconnect access and the target network’s controls can be bypassed or are insufficient, SS7 abuse can enable:

  1. Tracking a subscriber’s current or recent network location using mobile-network registration and serving-cell information
  2. Redirecting, intercepting or recording some mobile calls
  3. Intercepting SMS messages, including one-time authentication codes in some attack scenarios
  4. Collecting subscriber-routing information and communications metadata
  5. Disrupting mobile service, manipulating routing or enabling fraud and account takeover as part of a wider attack
  6. Supporting fraud by abusing trusted signalling functions or intercepted authentication messages

These are serious risks because they can expose confidential conversations, SMS-based authentication and a target’s movements without requiring conventional spyware to be installed first. They are not, however, equivalent to unrestricted control over the handset itself.

What SS7 Does Not Automatically Provide

SS7 access alone does not ordinarily give an attacker universal access to everything stored or displayed on a handset. Claims that the protocol automatically allows any attacker to activate the camera and microphone, recover every password, read all encrypted application content or delete all text messages collapse several distinct attack methods into one.

Those outcomes generally require another capability, such as spyware on the endpoint, exploitation of the operating system, access to an online account, abuse of a mobile application, compromise of a backup, or physical access to an unlocked device. More than one pathway may also be used in sequence. For example, interception of an SMS code could help an attacker enter an account, after which the account compromise produces the wider data exposure.

Accurate scoping is therefore essential. It avoids both extremes: dismissing a genuine network-level risk because no spyware was found, or attributing every device symptom to a sophisticated telecommunications attack.

Five Mobile Surveillance Pathways

Pathway Potential Exposure Evidence and Investigative Limits
Signalling or interconnect abuse Approximate location, routing data, some call or SMS redirection or interception, and service disruption Relevant records may sit primarily with telecommunications operators. A handset examination may not prove or exclude a transient network event.
Rogue base station or cell site simulator Device and subscriber identifiers, location, metadata and, in some configurations, communications exposure or forced network downgrade Assessment may require radio-frequency context, carrier information and timing. Historical proof can be difficult after the equipment is gone.
SIM swap or subscriber account takeover Control of the mobile number, incoming calls and texts, password resets and SMS authentication codes Carrier account records, identity-verification events, service interruptions and account notifications may be more probative than handset artefacts alone.
Spyware or device compromise Messages, files, microphone, camera, location, credentials and application data, depending on privileges and tooling A properly scoped forensic examination may identify artefacts, but absence of a finding is not a guarantee that compromise never occurred.
Cloud or messaging account compromise Synced messages, contacts, backups, email, location history, tokens and account settings Investigation should cover identity, cloud, email, recovery methods, active sessions and logs, not only the physical phone.

 

The pathways can overlap. A credible investigation should test the hypotheses that fit the known facts instead of selecting a single explanation at the outset.

What Encrypted Communications Protect

End-to-end encryption is an important control because it is designed so that message content is readable only at the communicating endpoints. It can reduce the value of interception in the network and is preferable to ordinary SMS or unencrypted voice for sensitive conversations.

Encryption is not a complete mobile-security strategy. It does not protect a message after an authorised recipient exposes it, and it cannot secure content displayed on a compromised endpoint. Depending on the service and configuration, metadata, notifications, cloud backups or linked devices may remain relevant. Account recovery and session security also matter.

High-risk users should combine appropriately configured end-to-end encrypted communications with strong device security, protected accounts and clear operational procedures. The United States Cybersecurity and Infrastructure Security Agency also recommends phishing-resistant authentication and advises highly targeted individuals to avoid SMS as a primary multifactor method where stronger options are available.

Can Forensic Examination Detect a Network Attack

A mobile forensic examination can be valuable, but its conclusions must stay within the evidence examined. It may identify malicious applications, configuration changes, suspicious permissions, persistence mechanisms, account artefacts, indicators of compromise, unusual communications or evidence that helps distinguish device compromise from another cause.

A signalling-only event may leave little or no durable artefact on the handset. Relevant evidence may instead exist in carrier records, account logs, authentication history, communications records, network telemetry or contemporaneous observations. Some of that information is controlled by third parties and may be retained only for a limited period.

This is why a negative handset result must be expressed carefully. It means the examination did not identify reportable evidence within the agreed scope, available data, methods and observation period. It does not prove that no interception, account misuse or transient compromise ever occurred.

NSI Global’s forensic spyware and malware detection service can form one part of a broader investigation. Where the facts indicate network, identity or account exposure, the scope may also need carrier liaison, account review, timeline analysis and examination of related devices or services.

Specialist Live Testing for SS7 Targeting

Where SS7-based targeting or network-level location tracking is a credible concern, NSI Global can extend the investigation beyond conventional handset forensics. Under controlled conditions, the suspect subscriber SIM can be placed into a specialist secure test handset equipped with a dedicated baseband firewall. The system continuously monitors cellular network and baseband activity for events associated with hostile or abnormal signalling, including attempts to track the subscriber through SS7-based mechanisms, silent SMS, rogue base stations and IMSI-catcher activity.

This is materially different from scanning the original phone for spyware. The monitored handset is used as an instrument to observe how the subscriber identity is being treated by the mobile network. If suspicious signalling or tracking activity occurs during the observation period, the system can generate indicators that help distinguish a network-level threat from an endpoint compromise.

The limitation is equally important: live monitoring is prospective. A clean observation period does not prove that the subscriber was never targeted previously, and a signalling attack that occurred before testing may have left little or no durable evidence on the original handset. Findings therefore need to be considered alongside the incident timeline, carrier records, account evidence, roaming history and any other available forensic artefacts.

Hardened Encrypted Communications for High-Risk Users

Where the assessed threat level warrants stronger protection than a conventional consumer smartphone or standard messaging application can provide, NSI Global can supply specialist hardened encrypted communications devices to properly vetted corporate or government clients.

These systems are intended for confidential voice and messaging and are designed around a hardened security architecture and strong cryptographic controls. They form part of a broader communications-security strategy rather than a substitute for sound device security, identity protection, operational procedures and threat-appropriate user practices.

NSI Global does not provide these systems as ordinary consumer retail products. Access is subject to strict purchaser due diligence, client vetting and suitability assessment, with the public NSI offering restricted to properly vetted corporate or government clientele.

For clients facing a credible mobile-surveillance or interception threat, this allows an engagement to move beyond identifying how communications may have been exposed. NSI Global can also advise on and, where appropriate, provide a hardened communications environment aligned with the client’s threat profile and operational requirements. Read more about NSI Global Communications Security and encrypted communication devices.

What to Do If Mobile Interception Is Suspected

Preserve Potential Evidence Before Making Changes

If the device may contain evidence required for court, an employment matter or another formal process, do not reset it, replace the SIM, remove suspected software or install consumer detection tools before receiving professional advice. These actions can alter timestamps, remove artefacts and make later findings harder to interpret.

Use a separate trusted device and communications channel to seek assistance. Record relevant dates, times, messages, account alerts, unexplained service losses and people with access to the device, but do not experiment with the suspected phone. If personal safety is at immediate risk, contact emergency services first and follow their instructions.

For more detailed preservation steps, read Spyware Concerns Here Is How to Safeguard Your Phone and Computer.

Contact the Mobile Provider Promptly

Ask the provider to check for unauthorised SIM replacement, number transfer, account changes, forwarding, new eSIM activation or other abnormal subscriber events. Request that relevant records be preserved where appropriate. Do not assume frontline support can investigate signalling abuse, but carrier account records may quickly confirm or exclude common forms of subscriber fraud.

Secure Accounts From a Trusted Device

Review primary email, cloud, messaging and carrier accounts from a separate trusted device. Revoke unknown sessions, correct recovery details and replace exposed credentials with unique passwords. Prefer phishing-resistant authentication, such as a security key or passkey, where the service supports it. Avoid moving a suspected compromise from one device to another through an unexamined backup.

Obtain an Investigation That Matches the Risk

Provide the investigator with a chronology and the reason for concern. The scope should reflect the suspected pathway, the value of the information, possible threat actors, travel and roaming history, legal requirements and whether expert evidence may be needed. A basic diagnostic check is not equivalent to an evidential forensic examination.

Security Measures for High Risk Mobile Users

Executives, legal teams, journalists, government personnel, people involved in sensitive disputes and others with elevated exposure should use layered controls:

  1. Keep the operating system and applications on supported, current versions
  2. Use a strong device passcode and restrict what appears on the lock screen
  3. Protect the mobile-provider account with the strongest available account controls
  4. Replace SMS authentication with passkeys, security keys or authenticator methods where feasible
  5. Use appropriately configured end-to-end encrypted communications for sensitive content
  6. Where risk warrants it, consider specialist hardened encrypted communications equipment supplied by NSI Global to properly vetted corporate or government clients
  7. Review linked devices, active sessions, recovery methods and forwarding settings
  8. Separate highly sensitive communications from general-purpose accounts and devices where risk warrants it
  9. Establish travel, loss, seizure and incident procedures before an event occurs
  10. Obtain specialist advice when the threat profile exceeds ordinary consumer guidance

Device-specific measures are covered separately in NSI Global’s Android spyware protection white paper and iPhone spyware protection guidance. Organisations reviewing secure communications can also examine NSI Global’s Communications Security (COMSEC) capability, including specialist encrypted communication devices for appropriately vetted clients.

How NSI Global Can Assist

NSI Global can help clients distinguish between device compromise, account misuse and other mobile-interception hypotheses, then define an investigation proportionate to the risk and intended use of the findings.

Depending on the circumstances, assistance may include forensic examination of mobile devices, review of account and communications evidence, preservation planning, timeline reconstruction, coordination with legal advisers, specialist live monitoring for network-level targeting of a suspect subscriber SIM, and the provision of hardened encrypted communications solutions to properly vetted corporate or government clients where the assessed threat profile warrants them.

This enables NSI Global to address the problem across the full lifecycle: determine whether the likely exposure sits at the device, account, radio or telecommunications-signalling layer; preserve and analyse relevant evidence; test for active network-level targeting where appropriate; and recommend or provide a more secure communications architecture for ongoing use.

No legitimate examination should begin with a guarantee that a device is clean or compromised. The objective is a defensible finding that states what was examined, what was identified, what could not be determined and what further work may be justified.

To discuss a suspected mobile-interception matter in confidence, contact NSI Global or call 1300 000 NSI (674) from Australia.

Frequently Asked Questions

Can Someone Track a Phone Through SS7?

An actor with suitable telecommunications-network access may exploit signalling weaknesses to estimate a device’s location. The precision, persistence and feasibility depend on the network, available access and defensive controls. Ordinary possession of a phone number does not by itself give every person this capability.

Can SS7 Turn On a Phone Camera or Microphone?

SS7 abuse does not ordinarily provide direct control of the handset camera or microphone. Those functions generally require device compromise, spyware, operating-system exploitation, a malicious application or another form of endpoint access.

Does End to End Encryption Stop Mobile Interception?

It can protect message content against some network interception, but it does not protect a compromised endpoint, exposed account, unsafe backup or recipient. It also does not necessarily conceal all metadata.

Can NSI Global Provide Hardened Encrypted Communication Devices?

Yes. Where the assessed threat profile warrants stronger communications protection, NSI Global can supply specialist hardened encrypted communication devices for confidential voice and messaging to appropriately vetted corporate or government clients. Access is subject to purchaser due diligence and suitability assessment. These systems form part of a layered security strategy and do not replace sound endpoint security, identity protection or operational procedures. View NSI Global’s encrypted communication device capability.

Can a Forensic Examination Prove That SS7 Was Used?

Not always. A signalling attack may leave limited evidence on the handset. In appropriate cases, specialist live monitoring can place the suspect subscriber SIM into a controlled secure test handset and monitor for SS7-based location-tracking attempts and related cellular threats during the observation period. That can provide useful contemporaneous indicators, but it does not retrospectively prove that every earlier event occurred. A defensible assessment may still require carrier records, account logs, network information and a reliable timeline in addition to device analysis.

Should I Factory Reset a Phone I Believe Is Monitored?

Not if evidence may be required. A reset can remove or alter useful artefacts. Use a separate trusted channel and obtain professional advice before changing the suspected device. Personal safety takes priority where there is an immediate threat.

A Precise Diagnosis Produces a Better Response

Mobile interception is a genuine security issue, but it is not one technique with one set of symptoms. Signalling abuse, rogue radio infrastructure, subscriber fraud, account compromise and spyware expose different information and leave different evidence.

The strongest response is therefore evidence-led and appropriately scoped. Preserve the device, protect immediate safety, secure accounts through a trusted channel and investigate the pathways that match the known facts. That approach is more useful than either dismissing the concern or promising that one scan can answer every question.

Sources and Further Reading

  1. 60 Minutes Australia — Bugged, Tracked, Hacked (2015)
  2. Security Research Labs — Ethical Hackers Can Help Reduce SS7 Abuse (17 June 2025)
  3. NIST Mobile Threat Catalogue Obtaining Device Location via SS7 Exploit
  4. MITRE ATT and CK Impersonate SS7 Nodes
  5. MITRE ATT and CK Interconnection Filtering
  6. CISA Mobile Communications Best Practice Guidance
  7. ComputerWeekly and 60 Minutes Australia Mobile Phone Users at Risk as Hackers Bug and Track Victims
  8. NSI Global — Corporate COMSEC Products: Encrypted Communication Devices
  9. NSI Global — Communications Security Solutions for Corporate and Government Sectors

 

Secure your peace of mind