Researchers at i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe introduced 5G-Shark, a low-cost rogue-5G-cell auditing tool that exploits unauthenticated cell-reselection broadcasts to draw nearby idle devices to a fake base station without jamming or malformed traffic. Testing against commercial 5G Standalone networks found that permanent subscriber identities were generally protected, but near-sequential, predictable rotation of temporary GUTI identifiers enabled linkage of 84% to 96% of consecutive registrations in some operator deployments, creating a persistent subscriber-tracking risk.
The researchers also used crafted unauthenticated Registration Reject messages to force radio-access downgrade and denial-of-service conditions. A Samsung Galaxy S23 could be pushed into limited-service 3G, an infinite retry loop, or a modem state requiring manual reset. The study attributes predictable temporary-ID allocation to operator or vendor implementation choices, while exposure to identity requests and pre-authentication rejection messages reflects limitations in the 5G specification; operators should assess identifier-allocation behavior and device resilience to unauthenticated signalling.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
Oscar Lasierra, Gines Garcia-Aviles, Antonio Skarmeta, and Xavier Costa-Pérez submitted the 5G-Shark paper as a preprint. The paper describes a low-cost rogue 5G cell that exploits unauthenticated cell reselection without jamming or malformed packets and distinguishes protocol-design limitations from deployment implementation gaps.
Researchers from i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe used the 5G-Shark rogue-cell methodology to assess commercial 5G deployments. They found near-sequential temporary GUTI reassignment in some networks, enabling linkage of 84% to 96% of consecutive registrations, and demonstrated crafted Registration Reject messages that downgraded or caused denial-of-service states on a Samsung Galaxy S23.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.