Fink Telecom Services (FTS) is a Switzerland-linked telecom signaling and SMS routing company that has been associated with commercial mobile surveillance activity exploiting weaknesses in SS7 and Diameter roaming ecosystems. Reporting has linked FTS-related identifiers, hostname patterns, and attack timing overlaps to a surveillance cluster that conducted long-running covert location-tracking operations against mobile subscribers across multiple countries. The activity associated with this ecosystem used telecom signaling abuse rather than conventional endpoint malware. Observed tradecraft included SS7 probing to obtain subscriber information, Diameter-based location queries, manipulation of signaling metadata and routing fields to obscure origin and influence message paths, and use of multiple operator identities across jurisdictions. In one observed campaign, the operator switched between SS7 and Diameter techniques and rotated apparent network identities to evade signaling defenses while attempting to track a high-profile target. In another, the activity combined SS7 probing with a SIMjacker-style zero-click binary SMS exploit targeting the SIM card through the S@T Browser, followed by additional Diameter queries intended to derive or refine device location. The broader operational pattern is consistent with a centralized commercial surveillance platform supporting intelligence-style customers. Historical telemetry tied to the linked activity showed multi-year persistence and large-scale location-tracking attempts against subscribers in numerous countries. High-confidence reporting associates FTS with telecom signaling access and platform capabilities that can enable interception and location tracking, but does not directly attribute the observed campaigns to a specific government customer. Fink Telecom Services is therefore best characterized as a commercial surveillance vendor or enabling entity in the telecom surveillance ecosystem rather than a publicly confirmed state-sponsored intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.