5G‑Shark Lures Phones onto Rogue 5G Cells, Harvests IDs and Forces Downgrades
What Happened — Researchers released a proof‑of‑concept called 5G‑Shark that impersonates a legitimate 5G base station, convinces nearby smartphones to attach, captures subscriber identifiers (IMSI/MSISDN) and can force a downgrade to older radio technologies—all without any network jamming.
Why It Matters for Trust & Control Assurance
- Demonstrates a blind spot in continuous monitoring of the Radio Access Network (RAN) for unauthorized cells.
- Highlights the need for auditable detection controls that generate defensible evidence of rogue‑cell activity.
- Directly tests the control objective “detect and respond to unauthorized network access,” a single objective that maps to many frameworks (e.g., NIST CSF 2.0, ISO 27001).
Who Is Affected – Mobile network operators, telecom equipment vendors, enterprises that rely on cellular connectivity for critical workloads, and device manufacturers.
Recommended Actions
- Map the “detect unauthorized network access” control to your audit framework of record.
- Deploy continuous RAN monitoring tools capable of identifying rogue base stations and unexpected downgrades.
- Collect and retain radio‑level logs (cell IDs, attach requests, downgrade events) as evidence for audit readiness.
- Validate detection rules against the 5G‑Shark methodology and adjust thresholds accordingly.
Technical Notes – The attack leverages a rogue base station that broadcasts legitimate‑looking 5G identifiers; no CVE or software flaw is required. Data harvested includes subscriber IDs (IMSI, MSISDN). No network jamming is used, making detection by traditional RF‑interference monitors ineffective.
Source: HackRead – 5G‑Shark Lures Phones to Rogue 5G Cells Without Network Jamming