A rogue femtocell in the wild.

Anatomy of a Mobile Attack Chain:

From RRC Downgrades to iOS Trust Cache Sabotage.

Posted by Isabella on May 26, 2026

Anatomy of a Mobile Attack Chain, and what to do about it

To truly understand a complex mobile cyberattack, there is little point in looking at isolated error messages. A faltering app or a dropping network signal seems like just an everyday bug at first glance. The actual modus operandi only becomes visible when you look at these two elements simultaneously and overlay the timelines. Only in that combination do you get a view of the whole picture. The breakdown below of an iPhone 13,1 over a two-month period shows exactly how those puzzle pieces fit together...

...

Disclaimer: Shown logos (such as ING) are the property of their respective owners and are used exclusively for forensic and educational purposes.

This article provides a detailed breakdown of a mobile campaign (target: iPhone 13,1 / iOS 14.8.1 - Build 18H107) over a period of two months.
The data reveals:

  • Radio frequency manipulation: forcing a phone via radio waves to an outdated, unsecured network protocol (e.g., 2G, 3G), deployed to intercept network traffic and facilitate and mask local intrusion attempts in, for example, banking sandboxes.
  • Structural sabotage of the iOS update mechanism: software blocking of security updates on the device itself, to prevent the operating system from patching vulnerabilities via software updates (and thus removing the malware).

Within digital forensics and malware analysis, incidents are often viewed in silos: network logs are separated from application crashes, and kernel artifacts are analyzed separately from the infrastructure. However, a coordinated campaign by an Advanced Persistent Threat (APT) only truly becomes visible when we chronologically overlay these data sources.

Phase 1: Radio Wave Manipulation and Interception (May 2022)

This analysis focuses on the May 2022 campaign in the ether. Analysis of the Baseband telemetry log-bb-stats.crash / Unknown (null).crash shows that the device was systematically subjected to Radio Resource Control (RRC) Downgrade Attacks. Through targeted disruptions, the modem chip was forced to leave secure LTE/5G networks rat=1000/1001 and connect to unsecured legacy protocols rat=0 for 2G, rat=2 for 3G.

Two critical anomalies stand out in the log files:

  • May 10, 2022: The device registers an aggressive series of disconnects via modemErr=145 (Network Reject). The modem is repeatedly forced to rat=0 (2G) within a short time frame (at 16:57:11, 18:53:16, 18:53:46 and 18:54:36).
  • May 11, 2022: An extreme hostage situation occurs at 09:48:40. The mobile broadband connection drops and the device is held continuously on the outdated 2G network via an active network reject for no less than 1440 seconds (24 minutes, exactly 24 minutes and 00 seconds). Later that day, this repeats at 13:22:15 for 510 seconds (exactly 8.5 minutes).

The Tactical Goal:

Prolonged and down-to-the-second isolation of a mobile device on a 2G network — such as the exact hostage-taking of 1440 seconds (24 minutes and 00 seconds) — statistically rules out natural network noise. This is a classic indicator of a pre-programmed script from an IMSI catcher or femtocell (a rogue cell tower, operationally often hidden mobile in the vicinity of the target). Because the outdated 2G protocol lacks mutual authentication, the attacker can assume a Man-in-the-Middle (MitM) position. This makes it possible to intercept and forward all network traffic live, and capture critical SMS messages such as Two-Factor Authentication (2FA) tokens.

Phase 2: The Banking Sandbox Breach (May 2022)

Once the network traffic ran through the malicious network infrastructure (2G), the attack vector shifted to the local application layer. Crash reports of the mobile ING Banking application be.ING.OneApp on May 20 and May 30, 2022 show what happens when malware attempts to interact with the active working memory (RAM) of a banking app.

Both crashes generate an identical hardware interrupt:

Plaintext
Exception Type: EXC_BREAKPOINT (SIGTRAP)
Exception Codes: 0x0000000000000001, 0x0000000102662f0c
Termination Reason: SIGNAL 5 Trace/BPT trap: 5 
Triggered by Thread: 13 
            

An EXC_BREAKPOINT (SIGTRAP) means the application triggered runtime protection after an illegal modification attempt or debugger attachment was detected within its own sandbox. The backtrace of the crashed thread reveals the exact line of defense:

Plaintext
Thread 13 name: Dispatch queue: TrusteerWrapper
0 libsystem_kernel.dylib      0x00000001bc939cf8 mach_msg_trap + 8
1 libsystem_pthread.dylib     0x00000001d84f0bc0 _pthread_cond_wait + 1224
2 tazSDK                      0x00000001035dfc68 0x103400000 + 1965160
3 tazSDK                      0x0000000103614084 0x103400000 + 2179204
4 INGTrusteerUploader         0x0000000102662f0c 0x1025a0000 + 798476             

The subsystems tazSDK and INGTrusteerUploader belong to IBM Trusteer Rapport, an enterprise anti-fraud framework deeply integrated into the banking app. Trusteer monitors the runtime environment for code injection (hooking), memory overlays (fake login screens or sensory recordings), and active process debugging.

The chronological correlation on May 20, 2022 shows the chain:

  • 11:05:18: The baseband registers an abrupt downgrade to rat=0 (2G).
  • 11:27:09: The banking app is initiated.
  • 11:27:23: Exactly 14 seconds later, tazSDK detects memory manipulation, after which the Trusteer wrapper forces the app to crash SIGTRAP to protect the session and the bank account.


Phase 3: Escalation to System Sabotage and Persistence (June 2022)

To prevent the deployed zero-day exploits from being wiped out by a regular iOS security update, the operating system's Over-The-Air (OTA) update mechanism was sabotaged.

Between May 12 and June 30, 2022, ten consecutive update attempts OTAUpdate-*.ips failed with an identical error:


JSON 
{ 
"restore_type": "OTAUpdate" 
"os_version": "18H107", 
"bug_type": "183", 
"restore_error": "39", 
"name": "iPhoneRestore" 
}																						

Deeper telemetry in the execution thread shows where the OS irrevocably aborts:


Plaintext
Entering handle_brain_is_loadable
Unable to load trust cache: 0xe00002d8
MobileSoftwareUpdateErrorDomain error 39 - Failed to load update brain trust cache

The Trust Cache Hostage Situation

When iOS starts an update, it first downloads the "Update Brain", the temporary framework that prepares the installation. The kernel mandatorily validates the signature of this code beforehand against the Trust Cache (the cryptographic database in the iPhone's Secure Enclave containing the mathematical hashes of legitimate Apple firmware).

The specific error code 0xe00002d8 (Access Denied) combined with MobileSoftwareUpdate Error 39 shows that the manipulated network environment corrupted the transfer of the cryptographic validation files. By blocking the successful verification of the Update Brain against the trust cache, the OS 'thinks' with every automatic update that the patch is corrupt, causing the installation to be aborted immediately.

The interception infrastructure thus enforces its own survival (persistence) on the network layer: the device is effectively held hostage on the outdated and vulnerable firmware baseline 18H107, allowing the Man-in-the-Middle proxy to remain operational.

Conclusion & what to do about it

The documentation demonstrates that modern mobile threats do not operate purely via software, but combine radio-infrastructure attacks with deep cryptographic hostage-taking. The structural occurrence of MobileSoftwareUpdate Error 39 in combination with inexplicable baseband RAT degradations is a compelling indicator that the integrity of the communication environment has been fully compromised.

Yet, there is an important, constructive lesson in this forensic battle. The different vectors require a fundamentally different approach to security:

  • The end user: today (since late 2023 / early 2024 with iOS 17.4 and Android 12) blocking 2G networks is available as a standard option in consumer versions. But ... on iOS it is packaged within 'Lockdown Mode', which in turn has a substantial negative impact on the user experience: images are not loaded or not loaded properly, design components loaded via CDNs risk failing completely.
  • The physical layer: a network attack via a rogue femtocell or IMSI catcher is located in the ether. Because this manipulates the hardware radio connection, this type of threat can ultimately only be effectively neutralized by tracking down and removing the physical source (the rogue cell tower).
  • The application layer (Software): against advanced software threats, such as sensory recordings (screen-scraping) that the Trusteer security in this example fought against log-bb-stats.crash, developers can arm apps using the principle of a Scrambled keypad, to at least blind sensory malware.

    ...

A forensic reality, The fortress holds (for now)

This dossier exposes a fundamental bottleneck, but at the same time shows a hopeful reality. The positive news is that modern Apple devices are heavily digitally armed. The hardware fortress—the Secure Enclave and Trust Cache validation—did exactly what it was designed to do in this scenario: it recognized the network manipulation and rigorously closed the data ports to protect vital bank details and account keys.

The dark side, however, is infrastructural. When a threat actor positions a physical, malicious cell tower (femtocell) in the immediate vicinity of the target, the dynamics shift. Against such a persistent radio diversion, it is ultimately a matter of time for any device: the constant bombardment with manipulated handshakes exhausts the system, forces updates to a halt, and creates permanent, unacceptable environmental friction.

The real blind spot therefore lies in the lack of correlated monitoring across the entire chain. As long as network telemetry, mobile endpoint integrity, and application crashes continue to be analyzed in strictly separated silos, these kinds of coordinated, hybrid campaigns will continue to fly under the radar... Until someone puts the puzzle together, of course.

In the next article:
The radio-frequency hijacking in the ether was just the opening move of this campaign. Once the devices left radio isolation, the battlefield moved to an even more sophisticated level: a prolonged, mathematical war of attrition on the HTTPS tunnels via the persistent injection of rogue certs. In our next article, we dissect the deeper network telemetry and expose the 'Smoking Gun' of the persistent Man-in-the-Middle (MITM) attacks, using an exclusive, multi-year chronological reconstruction of the cryptographic trust engine via security-sysdiagnose.txt.