Skip to content
← RegistryDossier · 5 steps · 4 edges

5G core GTP-U user-plane injection → subscriber MITM

Attacker on a transit network between mobile-core hops (or with compromised UPF). GTP-U packets are typically unfiltered between PEs; inject packets into subscriber bearers — credential capture, free-of-charge tunnels, downstream attacks.

Filed by AD Knowledge Base
§ Kill-chainDrag · zoom · scroll

§ Context

Assumed environment: target operates a 5GC / 4G EPC with insufficient GTP-U filtering between user-plane functions and transport network. Attacker has internal foothold on transit infrastructure.

§ Steps

  1. 01
    Foothold on transit / shared infraInitial Access
    T1078Valid Accounts
  2. 02
    Capture app-layer creds / tokensCredential Access
    T1539Steal Web Session Cookie
  3. 03
    MITM subscriber data sessionCredential Access
    T1557Adversary-in-the-Middle
  4. 04
    Identify GTP-U traffic between UPFsCredential Access
    T1040Network Sniffing
  5. 05
    Spoof GTP-U packet into target bearerLateral Movement
    5G-GTP-UGTP-U User-Plane Spoof

§ References

§ Frequently asked

What is the "5G core GTP-U user-plane injection → subscriber MITM" attack path?
Attacker on a transit network between mobile-core hops (or with compromised UPF). GTP-U packets are typically unfiltered between PEs; inject packets into subscriber bearers — credential capture, free-of-charge tunnels, downstream attacks. It chains 5 steps drawn from real-world offensive-security techniques.
What starting position does this attack require?
The first step is Foothold on transit / shared infra (T1078) — a initial access primitive. Assumed environment: target operates a 5GC / 4G EPC with insufficient GTP-U filtering between user-plane functions and transport network.
What is the final impact of this kill-chain?
The final step lands on Spoof GTP-U packet into target bearer (5G-GTP-U), which falls under Lateral Movement. From here, an operator typically pivots into post-exploitation or maintains persistence.
How can defenders detect or prevent this attack?
Detection and prevention vary per step. Refer to each linked MITRE ATT&CK entry under "References" — every technique on that page lists defensive controls, detection telemetry, and known threat-actor usage.

§ Related dossiers