Researchers have discovered a new type of IMPersonation Attacks on 4G LTE networks, called IMP4GT, which allow hackers to exploit the lack of data integrity protection for users and inject malicious content by impersonating victims. 4G Long Term Evolution, or LTE, is the latest mobile communication standard and is used by hundreds of millions of people worldwide for fast internet. 4G LTE impersonation attacks (IMP4GT) can also inject arbitrary packets and gain access to the payloads of existing packets. The IPV4 protocol on Android and the IPV6 protocol on iOS and Android are vulnerable to IMP4GT attacks, while all LTE devices, such as mobile phones, laptops, tablets and many others, are also affected.
The researchers used two different impersonation attack variants on a commercial LTE network to breach common authentication and execute the impersonation attacks with the help of the open-source LTE Software Stack srsLTE from Software Radio System.
- The first variant is uplink impersonation. In Uplink impersonation, hackers are able to bring victims onto networks and use arbitrary IP services, such as websites, with the victim's identity. During the impersonation attack, all traffic generated by the hacker is associated with the IP .
- The second variant involves downlink impersonation, which allows a hacker to create a TCP/IP connection to the phone that bypasses any LTE network firewall mechanism. The hacker cannot breach any security mechanism above the IP layer. This means that the hacker can bypass any authorization, accounting, or firewall of a provider. The researchers are conducting experiments to confirm their speculation and demonstrate what an IMP4GT actually does in a setup. As a result, they can gain access to a service's website, which only the user should have access to, or bypass the provider's firewall.
The researchers compare this attack method to IMSI catchers /Stingrays that can operate successfully at distances of up to about 2km. In both of these attacks, the hacker simulates a malicious network towards the victim. This attack affects all network providers, thus making all networks equally vulnerable, a situation that is expected to be corrected with upcoming 5G.
