The Link Between Apps, Smartphones, and Ballistic Missiles

The cellphone is ubiquitous. Its presence in boardrooms and battlefields is a sign of a technology that has become indispensable to its users. However, it can be a deadly distraction and an Operational Security weakness that pinpoints users for enemy weapons and targeting systems. Whether the user is in Ukraine or the Middle East, cellphone emanations and the data that users choose to store on them have been used to target units. Uploaded images have embedded location data including GPS coordinates (latitude, longitude, and altitude) and timestamps stored inside a smartphone’s metadata. Pictures can also be quickly analyzed using commercially available software that can determine location based on background details. The lesson of communications security is being relearned despite the proven risk of social media and personal devices on the battlefield. The implications for military, security, law enforcement, and government should be obvious. Unfortunately, the same technology and techniques used to target military personnel can be used to identify anyone for criminal or terroristic purposes. The location data is available wherever cellphones are used.

Cellphones have been implicated in data intrusions against military and civilian targets since at least 2016 when it was revealed that malicious parties could gain direct access to cellphone networks through commercial leases. Ignorance was weaponized because of inconvenience and need to stay connected and overrode Operational Security (OPSEC) concerns. Outside of Sensitive Compartmental Information Facilities (SCIF) and other classified areas phones remain on and are reliable conduits for WhatsApp or Signal communication. However, the technology behind cell phones bears examination to clarify how much risk a phone is to the user. Absent a tactical faraday bag to block cellular (4G/5G), Wi-Fi, Bluetooth, GPS, and EMP signals, cellphones that lack this sort of signal blocking shielding can be tracked by “pinging” the phone number and verifying its location. Any signals sent by the phone will be picked up by cellular communication towers and the location data recorded. This theoretical vulnerability is already being exploited on the battlefield.

Iranian forces have leveraged these exact telecommunications flaws, specifically the Signaling System 7 (SS7) protocol used by 2G and 3G networks, to target American forces and contractors in the Middle East despite the flaws being known for over a decade. By combining SS7 network vulnerabilities with commercial advertising identifiers Iran has identified specific targets on US bases and personnel dispositions at hotel locations including those in Iraq and Bahrain. Data routinely collected by mobile apps to identify user locations was allegedly the key to uncovering those target clusters.

The SS7 flaws are a bonanza for intelligence agencies and criminals using spoofing tools to gather data while circumventing other methods that might raise alarms like Human Intelligence (HUMINT) surveillance. Data aggregators that buy, package, and sell location data gathered from apps and advertising are exploiting a massive oversight hole. Iran has a map of American troop locations because of the location data, troop social media posts and the social media posts of local observers. The data can then form the corpus of targeting data for conventional and unconventional weapons targeting. One of the risks from SS7 flaws is that specific users may be tracked. This is a chilling revelation, especially for potential targets of criminal or terrorist groups. Although the VIP or high-value target may have their devices and signals shielded, if their security detail or entourage is not otherwise shielded, they could serve as target vectors. Sophisticated collection efforts could also capture the specific details of specific devices correlated to high-payoff targets.

The risk to these targets increases exponentially when personnel deploy overseas and rely on local infrastructure. When US networked forces connect their devices to foreign telecommunications networks, they risk exposing their data through private business agreements that may include state adversaries. If American forces are using foreign telecommunications networks to connect their devices, they may be using networks that include other states opposed to the US; therefore, using foreign networks undercuts US device security. It is suspected that the same SS7 weaknesses noted since the system’s implementation in the 1970s are allowing for foreign targeting. The unauthenticated, plain text SS7 system may have allowed Iranian infiltrators to guide missiles to targets using location data gained through commercial links between Irancell and Gulf telecom carriers. Among the potential data that was available to Iran: communications between U.S. bases in Qatar, Bahrain, and Kuwait; activity and digital signatures, operational tempo, troop quartering locations. The data gathering techniques were not novel or unique and had been tested prior to the war with the US.

The same techniques used against Iran’s domestic protestors were turned against the US and its allies to confirm metadata, IP addresses, Wi-Fi connections, and satellite data available through commercial sources. As Gary Miller of Citizen Lab stated, “Turning off your GPS does nothing against the network your phone runs on…the phone is a beacon and leaks data through the network.” However, adversarial intelligence collection is not limited to exploiting physical networks; the threat is actively embedded in the software service members download. Recent analysis by Wired has revealed it’s not limited to cellphone towers and data leaks either. Applications and their source code can pull data through to unsuspected recipients.

Recent analysis by Wired has revealed one in eight apps built for US service members contain foreign code. Although Wired’s investigation didn’t find any active data flow to the apps built with code from China and Russia, apps specifically build for military members known as Military-Marketed Mobile Apps (MMM-apps) collect private data using the same mechanisms as general-purpose apps. The difference is that the data belongs to military-affiliated personnel and could be a security risk. The data risk previously posed by fitness trackers is being replicated by cellphones and ad data tracking apps to compile data maps profiling everything from pattern of life activities to potential classified work locations. Some data could also be put to use by an intelligence entity to coerce information from compromised persons. The data aggregated by apps and sold by data brokers is assuming the shape of private intelligence, even data obtained from foreign sources on American military from ad sources.

The combination of app derived data that can be legally acquired by foreign intelligence services and the data “pings” to telecommunications relays that can be used to confirm locations create an operational security feedback loop that has resulted in fatal consequences. The cellphone may not the sole culprit, but it contributes to the erosion of situational awareness and operational security necessary for a focused adversary to identify and strike targets. Precision strikes are not simply deadly because of their explosive yield but also because they strip away any sense of anonymity on the battlefield. Precision strikes against high-value targets can be devastating. The lesson to be learned from Iran gaining the intelligence to target US forces through exploitation of ‘70s era technology to strike sophisticated weapons systems is clear. Overreliance on unshielded and unvalidated communications systems has created operational gaps that must be closed. Personnel must also understand that their smartphones are minicomputers capable of beckoning to foreign intelligence and weapons through the data they create on unclassified networks. The very data created as individuals yield their phones provides a rich ecosystem for exploitation.

Dr. John Ringquist is a first-year instructor at the Command and General Staff School teaching in the Department of Joint, Interagency, Multinational Operations.

He was an Army Foreign Area Officer (FAO) prior to his retirement in 2024. Prior to his current duties at Fort Leavenworth, he most recently served as the Senior Defense Official/Defense Attache for Angola and Sao Tomé in Luanda, Angola 2021-2023. Prior to his service in the U.S. Embassy Luanda, he served as a regional branch chief in the U.S. AFRICOM J-52 West Africa Division at Stuttgart, Germany. In this position he managed planning efforts between thirteen West Africa and Sahel nations, AFRICOM and service component staffs, interagency partners, NATO, and SOUTHCOM. He also provided oversight for all security cooperation and security assistance initiatives under his branch’s coordination authority. He also served as Senior Defense Official/Defense Attache for Sudan and Chad. John also served as the Army Attache and Senior Defense Official/Defense Attache in Dakar, Senegal with duties in Senegal, Cabo Verde, Guinea-Bissau, and The Gambia. Before joining the FAO community, John served in the Engineer Branch from which he deployed to the Middle East twice. He also served in Bosnia. As an enlisted soldier he was a part of the Joint POW-MIA recovery effort in Vietnam, Laos, Cambodia, and Thailand as an analyst/linguist.

Dr. Ringquist received his PhD in History from the University of Kansas, and a MPPA from the University of Missouri. He earned his commission from Officer Candidate School. He taught at West Point 2009-2012. John also taught courses in Intelligence Studies for the National Intelligence University, George Washington University, and Marymount University. His undergraduate degrees also encompass biology, microbiology, and history.

John has written numerous articles and commentaries for service journals, peer-reviewed publications, and security-related blogs. He is a prolific contributor to book projects and has contributed encyclopedia entries to ABC-CLIO for African terrorism topics. His writings include poetry and prose for Kansas City-area collaborative projects. In addition to his interest in military history and Africa, John has written about security, technology and innovation, climate, disease, and alternative energy. His present writing projects are centered around a series of volumes of oral history that include the Vietnam War, Global War on Terror, and post-conflict reintegration; a book about race relations in the American Civil War Trans-Mississippi Theater; and a book about the U.S. Army band members in the Global War on Terror. His fiction writing includes three volumes of collected short stories, a running column in Forbidden Futures magazine, and a plethora of flash fiction pieces.

He is the co-founder of Blue Feather LLC, an art collective and games workshop that provides an incubator space for young writers and creators to develop their artistic and business skills. Blue Feather LLC is also a hybrid makerspace for those seeking to work through service-related trauma through writing workshops, local poetry events, and art.

Related Articles

- Advertisement -

Latest Articles