Awesome Cellular Hacking
August 28, 2026 · View on GitHub
A comprehensive curated list of resources for 2G/3G/4G/5G cellular security research and analysis
This repository consolidates community knowledge in the cellular security space, including exploits, research papers, tools, and educational resources. The goal is to preserve and organize important security research that might otherwise become difficult to find.
Disclaimer: This information is intended for educational and defensive security research purposes only. Use responsibly and in compliance with applicable laws and regulations.
Table of Contents
- Getting Started
- Rogue Base Stations
- Recent Updates (2024-2026)
- Software and Tools
- Hardware Setup
- Testing and Research Methodologies
- Attack Vectors
- Conference Talks
- Research Papers
- Equipment and Hardware
- Detection and Defense
- Cellular IoT and NB-IoT Security
- Satellite-Cellular Integration
- Private 5G Network Security
- Network Slicing and Edge Security
- Automotive and Industrial Cellular
- Forensics and Investigation
- Vulnerability Disclosure
- SIM Security
- SS7 and Telecom Infrastructure
- Surveillance Technology
- Recent CVEs and Updates
- International Research
- Training and Education
- Vendor-Specific Research
- Roaming and Interconnect Security
- Community
- Resources
Getting Started
New to cellular security research? This section outlines the recommended path for building foundational skills.
Skill Levels
Beginner (passive listening only)
- Hardware: RTL-SDR V3 or V4 ($35-$40), a laptop running Linux
- Software: GNU Radio, GQRX, gr-gsm
- First project: Scan and decode GSM frames passively using gr-gsm and Wireshark
- Reading: NIST SP 800-187 LTE Security Guide
Intermediate (active research lab)
- Hardware: HackRF One or LimeSDR Mini ($139-$350), programmable SIM cards (sysmoUSIM), a spare Android device
- Software: srsRAN 4G, Open5GS or Free5GC, OsmocomBB
- First project: Build a private LTE network in a Faraday cage and connect a test device
- Reading: srsRAN documentation, Open5GS tutorials
Advanced (protocol fuzzing and baseband research)
- Hardware: USRP B210 or BladeRF 2.0, multiple test devices
- Software: 5GBaseChecker, LTEFuzz, BaseBridge, SigPloit, FirmWire, 5GHOUL
- Focus areas: Baseband fuzzing, RAN-Core interface testing, SS7/Diameter signaling
Lab Setup Checklist
- Linux host (Ubuntu 22.04 or 24.04 recommended)
- UHD drivers installed and device recognized (
uhd_find_devices) - Faraday cage or RF shielding for active transmissions
- Programmable SIM cards (sysmoUSIM-SJA2 or similar)
- Dedicated test devices (not your daily driver)
- Isolated network environment (no production network access)
Key Concepts to Understand First
- 3GPP Architecture Overview: how UE, eNodeB, MME, SGW, PGW fit together
- IMSI, IMEI, TMSI: subscriber identity fundamentals
- AKA Protocol: how authentication works in LTE
Rogue Base Stations
GSM/CDMA Traffic Impersonation and Interception
-
How To Build Your Own Rogue GSM BTS For Fun and Profit
Guide to creating a portable GSM BTS for private networks or security testing. Covers technical setup using relatively inexpensive hardware.
-
How to Create an Evil LTE Twin / LTE Rogue BTS
Tutorial for setting up a 4G/LTE Evil Twin base station using srsRAN and USRP SDR devices.
-
Practical Attacks Against GSM Networks: Impersonation
Detailed analysis of GSM base station impersonation using SDR and open source tools.
-
Tutorial: Analyzing GSM with Airprobe and Wireshark
Step-by-step guide for using RTL-SDR to analyze GSM signals with GR-GSM/Airprobe and Wireshark.
-
GSM/GPRS Traffic Interception for Penetration Testing
NCC Group research on GSM/GPRS interception capabilities for penetration testing engagements.
Recent Updates (2024-2026)
New Research (2025-2026)
-
SNI5GECT: Sniffing and Injecting 5G Traffic Without Rogue Base Stations — Singapore University of Technology and Design, USENIX Security 2025
Framework that enables sniffing unencrypted 5G messages and injecting attack payloads over-the-air without jamming or rogue base stations. An attacker within 20 meters can force devices to reboot and downgrade to 4G. GitHub
-
5Gone: Uplink Overshadowing Attacks in 5G-SA — ETH Zurich, Feb 2026
SDR-based uplink overshadowing attack against 5G-SA networks exploiting 3GPP standard deficiencies. Enables surgical DoS, privacy, and downgrade attacks with E2E latency under 500μs. Runs on standard x86 hardware without dedicated acceleration.
-
Kairos: Timing-Induced Interaction Failures in LTE and 5G Core Networks — 2026
Lightweight testing framework exposing timing-induced interaction failures. Discovered 20 new vulnerabilities and reproduced 34 existing issues across Open5GS, srsRAN, Amarisoft, and commercial implementations.
-
RANsacked: 100+ Flaws in LTE and 5G Implementations — University of Florida / NC State, Jan 2025
Researchers disclosed 119 vulnerabilities (97 CVEs) across seven LTE and three 5G implementations including Open5GS, Magma, OpenAirInterface, Athonet, SD-Core, srsRAN. Every flaw can be used to persistently disrupt city-wide cellular communications. Some require no SIM card — a single unauthenticated packet can crash an MME or AMF.
-
CITesting: Context Integrity Violations in LTE Core Networks — KAIST, ACM CCS 2025 (Distinguished Paper)
KAIST researchers identified a new class of uplink attacks against LTE core networks. Unlike traditional downlink attacks, these work through legitimate base stations and can affect anyone in the same MME coverage area. All four tested implementations (Open5GS, srsRAN, Amarisoft, Nokia) were vulnerable.
-
LLFuzz: LLM-Guided Baseband Firmware Fuzzing — KAIST, July 2025
LLM-guided fuzzing framework for cellular baseband firmware targeting MediaTek and Samsung Shannon. Discovered 11 memory corruption vulnerabilities including buffer overflows in NAS and RRC message handlers. Leverages LLM to generate semantically valid protocol messages.
-
Uncovering Hidden Paths in 5G: Protocol Tunneling and Network Boundary Bridging — ACM CCS 2025
New research on exploiting protocol tunneling in 5G networks to cross network boundaries and reach components that should be isolated.
-
BaseBridge: Over-the-Air and Emulation Testing for Cellular Baseband Firmware — IEEE S&P 2025
Bridges the gap between over-the-air and emulation-based testing for cellular baseband firmware analysis. Extends the FirmWire emulator.
-
From Control to Chaos: Formal Analysis of 5G Access Control — Penn State, IEEE S&P 2025
Comprehensive formal analysis of 5G's access control mechanisms, uncovering critical vulnerabilities.
-
Devilray: Adversarial Model Revealing Blind Spots in Fake Base Station Detection — May 2026
Systematic adversarial baseline exploring realistic FBS evasion strategies. Evaluates 7 detectors and identifies gaps in coverage across 2,592 feasible FBS configurations.
-
GLaDoS: Location-aware Denial-of-Service of Cellular Networks — USENIX Security 2025
Location-aware DoS attacks targeting specific geographical areas in cellular networks.
-
Breaking 5G on The Lower Layer — 2026
Lower-layer exploitation research presenting SIB1 spoofing and Timing Advance manipulation attacks during random access procedures.
-
5G Network Slicing: Security Challenges, Attack Vectors, and Mitigation — PMC, July 2025
Comprehensive classification of attacks across orchestration, virtualization, and inter-slice communication layers in 5G.
-
Survey on 5G Physical Layer Security Threats and Countermeasures — MDPI Sensors, 2024
In-depth review of PHY layer attack surface in 4G/5G: jamming, spoofing, eavesdropping, pilot contamination, and current SDR-based research tooling.
New Research (2024)
-
Hermes: Unlocking Security Analysis of Cellular Network Protocols — USENIX Security 2024
End-to-end framework to automatically generate formal FSM representations from natural language cellular specifications. Achieves 81-87% accuracy and uncovers 3 new vulnerabilities plus 19 previous attacks in 4G/5G specifications. GitHub
-
CellularLint: Identifying Inconsistent Behavior in Cellular Network Specifications — USENIX Security 2024
Semi-automatic framework for inconsistency detection in 4G/5G standards using few-shot learning on domain-adapted LLMs. GitHub
-
Logic Gone Astray: Security Analysis of 5G Basebands — USENIX Security 2024
Control plane protocol security analysis framework for 5G baseband implementations.
-
ASTRA-5G: Automated Over-the-Air Security Testing — WiSec 2024
Open-source framework automating security testing for 5G SA devices by leveraging enhanced core and RAN software. Research Paper
-
5GBaseChecker Tool Release — Penn State University, Black Hat 2024
Open-source tool for detecting vulnerabilities in 5G baseband implementations. Used to find 12 critical bugs in Samsung, MediaTek, and Qualcomm chipsets affecting Google, OPPO, OnePlus, Motorola, and Samsung devices.
Base Station Software and Tools (Updated)
- OpenBTS 2024 Reloaded — Updated for modern UHD drivers and Ubuntu 22.04/24.04
- OpenAirInterface (OAI) — Complete 3GPP Release-15+ implementation with active 5G development
- LimeNET CrowdCell — Network-in-a-box with integrated LimeSDR for small cell deployments
- Amarisoft LTEENB/gNB — Professional-grade LTE/5G NR base station software
- DragonOS — Debian/Lubuntu-based SDR distro with cellular tools pre-installed; supports RTL-SDR, HackRF, LimeSDR, BladeRF; latest release is DragonOS Noble (24.04). Website
- WarDragon — Passive RF sensor platform with AI-enhanced cellular survey capabilities; integrates with TAK; includes Ransack for multi-RAT survey
- Magma Core Network — Meta's distributed packet core, now under the Linux Foundation
- 5GBaseChecker — Automated 5G baseband vulnerability detection tool
- Ransack — Multi-RAT cellular survey/recon platform; unifies LTE/5G NR/GSM/NB-IoT observations from SDRs, Qualcomm phones, and Rayhunter into SQLite with REST API
- 5GHOUL — 5G NR fuzzing and attack framework targeting Qualcomm/MediaTek
Software and Tools
Base Station Software
| Software | Description | Link |
|---|---|---|
| OpenBTS (2024 Reloaded) | Updated Linux SDR-based GSM air interface for modern systems | GitHub |
| OpenBTS (Original) | Range Networks implementation | SourceForge |
| YateBTS | GSM/GPRS radio access network implementation | Website |
| srsRAN Project | Open-source 5G O-RAN CU/DU software suite | GitHub |
| srsRAN 4G | Open-source 4G software radio suite | GitHub |
| OpenAirInterface | Complete 4G/5G protocol stack | Website |
| Free5GC | Open-source 5G core network implementation | GitHub |
| Open5GS | Open-source 5G core and EPC implementation | GitHub |
| Kamailio | Open-source SIP server used in IMS/VoLTE labs | Website |
Configuration Guides
Analysis Tools
| Tool | Description | Link |
|---|---|---|
| Ransack | Multi-RAT cellular survey platform for DragonOS; merges LTE/5G NR/GSM/NB-IoT into unified DB; orchestrates srsRAN, LTESniffer, FALCON, Rayhunter | GitHub |
| Rayhunter | EFF's IMSI catcher detector for Orbic hotspots; detects 2G downgrades and suspicious requests | GitHub |
| 5GBaseChecker | Automated 5G baseband vulnerability detection (Penn State) | GitHub |
| 5GHOUL | 5G NR attacks against Qualcomm/MediaTek with stateful fuzzer | GitHub |
| FirmWire | Full-system baseband firmware emulation for fuzzing/debugging | GitHub |
| BaseBridge | Bridges OTA and emulation testing for baseband firmware | GitHub |
| LTE-Cell-Scanner | LTE cell detection and analysis | GitHub |
| gr-gsm | GSM analysis with GNU Radio | GitHub |
| IMSI-Catcher Detector | Android app for detecting IMSI catchers | GitHub |
| CellGuard | iOS app detecting rogue base stations via baseband analysis | GitHub |
| QCSuper | Capture 2G-4G traffic using Qualcomm phones | P1 Security |
| FALCON LTE | Fast analysis of LTE control channels in real-time | GitHub |
| Kalibrate | GSM base station scanner and frequency calibration | GitHub |
| LTE Sniffer | Open-source LTE downlink/uplink eavesdropper | GitHub |
| OsmocomBB | Free firmware for mobile phone baseband processors | Osmocom |
| Modmobmap | Mobile network mapping | GitHub |
| Modmobjam | Mobile jamming research tool | GitHub |
| CITesting | Context integrity violation testing for LTE core networks | ACM DL |
| SigPloit | SS7/Diameter/GTP/SIP signaling security testing framework | GitHub |
| LTEFuzz | LTE protocol fuzzer (KAIST) | GitHub |
| LLFuzz | LLM-guided baseband firmware fuzzing for MediaTek/Samsung Shannon | Paper |
| Crocodile Hunter | EFF tool for detecting rogue cell towers by wardriving | GitHub |
| SCAT | Signaling Collection and Analysis Tool for Qualcomm/Samsung | GitHub |
| Hermes | FSM synthesis from natural language specifications | GitHub |
| CellularLint | Inconsistency detection in 4G/5G standards | GitHub |
| 5GReasoner | Property-directed formal verification of 5G control-plane protocols | Paper |
| DoLTEst | Downlink negative testing framework for LTE devices; 1,848 test cases | Paper |
| ProChecker | FSM extraction + model checking for 4G LTE implementations | Paper |
| LTEInspector | Property-driven adversarial model-based testing for 4G LTE | Paper |
| BASECOMP | Comparative analysis for baseband integrity protection | GitHub |
| BaseTrace | Framework for iPhone baseband interface research | GitHub |
| ss7map | SS7 network exposure mapping | P1 Security |
| Osmocom Suite | Complete open-source GSM/GPRS stack | Osmocom |
Hardware Setup
USRP Installation on Linux
# Add Ettus Research repository
sudo add-apt-repository ppa:ettusresearch/uhd
sudo apt-get update
# Install UHD drivers and tools
sudo apt-get install libuhd-dev libuhd003 uhd-host
# Find connected devices
uhd_find_devices
# Download firmware images
cd /usr/lib/uhd/utils/
./uhd_images_downloader.py
# Test device connection
sudo uhd_usrp_probe
SDR Hardware Options
| Hardware | Frequency Range | Bandwidth | Price Range | Use Case | Link |
|---|---|---|---|---|---|
| Ettus Research (USRP) | |||||
| USRP B210 | 70 MHz - 6 GHz | 61.44 MHz | $2,100 | Professional development, 2x2 MIMO | Ettus |
| USRP B200mini | 70 MHz - 6 GHz | 61.44 MHz | $775 | Compact USRP B-series | Ettus |
| USRP N210 | DC - 6 GHz | 25 MHz | $1,700 | High-performance networked SDR | Ettus |
| USRP N320 | 1 MHz - 6 GHz | 200 MHz | $8,000 | Networked 2x2 MIMO | Ettus |
| USRP X310 | DC - 6 GHz | 160 MHz | $6,000 | High-performance desktop/rack | Ettus |
| USRP X410 | 1 MHz - 7.2 GHz | 400 MHz | $15,000 | Latest high-performance 4x4 MIMO | Ettus |
| USRP X440 | 30 MHz - 4 GHz | 1.6 GHz | $25,000+ | Latest 8x8 MIMO RFSoC platform | Ettus |
| USRP E320 | 70 MHz - 6 GHz | 56 MHz | $4,000 | Embedded 2x2 MIMO SDR | Ettus |
| Nuand (BladeRF) | |||||
| BladeRF 2.0 xA4 | 47 MHz - 6 GHz | 61.44 MHz | $420 | Budget 2x2 MIMO development | Nuand |
| BladeRF 2.0 xA9 | 47 MHz - 6 GHz | 61.44 MHz | $720 | High FPGA resources, 2x2 MIMO | Nuand |
| BladeRF x40 (Legacy) | 300 MHz - 3.8 GHz | 40 MHz | $400 | Entry-level legacy model | Nuand |
| Great Scott Gadgets | |||||
| HackRF One | 1 MHz - 6 GHz | 20 MHz | $350 | Budget TX/RX development | GSG |
| YARD Stick One | 300-348, 391-464, 782-928 MHz | 2.5 MHz | $110 | Sub-GHz IoT frequencies | GSG |
| Lime Microsystems | |||||
| LimeSDR USB | 100 kHz - 3.8 GHz | 61.44 MHz | $289 | Open-source 2x2 MIMO | Lime Micro |
| LimeSDR Mini | 10 MHz - 3.5 GHz | 30.72 MHz | $139 | Compact LimeSDR variant | Lime Micro |
| LimeSDR Mini 2.0 | 10 MHz - 3.5 GHz | 30.72 MHz | $169 | Updated with ECP5 FPGA | Lime Micro |
| LimeSDR X3 | Various bands | Up to 61.44 MHz | $3,000+ | Professional 3x transceiver PCIe | Lime Micro |
| Analog Devices | |||||
| PlutoSDR | 325 MHz - 3.8 GHz | 20 MHz | $150 | Education and learning platform | Analog Devices |
| RTL-SDR Blog | |||||
| RTL-SDR V3 | 500 kHz - 1.75 GHz | 3.2 MHz | $35 | Ultra-budget RX-only scanner | RTL-SDR |
| RTL-SDR V4 | 500 kHz - 1.75 GHz | 3.2 MHz | $40 | Latest with R828D tuner | RTL-SDR |
| Airspy | |||||
| Airspy R2 | 24 MHz - 1.8 GHz | 10 MHz | $200 | High-performance VHF/UHF scanner | Airspy |
| Airspy Mini | 24 MHz - 1.8 GHz | 6 MHz | $99 | Compact Airspy in dongle format | Airspy |
| Airspy HF+ Discovery | 9 kHz - 31 MHz, 60-260 MHz | 768 kHz | $169 | Dedicated HF reception | Airspy |
| SDRplay | |||||
| RSP1A | 1 kHz - 2 GHz | 10 MHz | $119 | Wideband general purpose | SDRplay |
| RSPdx | 1 kHz - 2 GHz | 10 MHz | $299 | Professional features, dual antenna | SDRplay |
| Red Pitaya | |||||
| STEMlab 125-14 | DC - 60 MHz | 50 MHz | $600 | HF transceiver, lab instrument | Red Pitaya |
| STEMlab 122-16 | DC - 50 MHz | Variable | $625 | High-resolution HF SDR/scope | Red Pitaya |
Common SDR Issues and Troubleshooting
| Issue | Possible Causes |
|---|---|
| Device not detected | Improper firmware, USB connection issues |
| Poor signal quality | Incorrect antennas, wrong frequency configuration |
| Connection failures | Wrong SIM, incorrect MCC/MNC codes |
| Performance issues | Virtualized platform limitations, wrong SDR firmware |
Testing and Research Methodologies
Modern Baseband Fuzzing (2024-2026)
-
SNI5GECT: Practical 5G Traffic Injection — USENIX Security 2025
Sniff and inject 5G messages without rogue base stations or jamming. Demonstrated 4G downgrade attacks within 20 meters of victim. GitHub
-
"NASty" 5G Baseband Vulnerabilities through Dependency-Aware Fuzzing — Black Hat USA 2025
Targeting Non-Access Stratum (NAS) layer vulnerabilities using dependency-aware fuzzing. Discovered security bypass using "!!FAKE-TESTHARNESS!!" message. Symbolic execution challenges with Samsung Shannon basebands requiring TB-level memory.
-
Budget-Friendly Baseband Fuzzing Setup — DefCon 32, Janne Taponen
Covers building cost-effective baseband fuzzing rigs using SDRs, using LLMs to accelerate protocol parser development, and testing automotive ECUs, payment terminals, and mobile devices.
-
RANsacked Fuzzing Framework — University of Florida / NC State, ACM CCS 2024
Domain-informed fuzzing approach targeting RAN-Core interfaces. Discovered 119 vulnerabilities across ten network implementations.
-
BaseBridge — IEEE S&P 2025
Framework that bridges over-the-air and emulation-based testing for cellular baseband firmware. Extends FirmWire.
-
FirmWire — NDSS 2022
Full-system baseband firmware emulation platform for Samsung and MediaTek. Discovered 8 remote memory corruptions including 3 pre-authentication RCE vulnerabilities.
Vulnerability Research Tools
- 5GBaseChecker — Automated 5G baseband vulnerability detection
- 5GHOUL — Stateful 5G NR fuzzer with OTA attack capabilities
- LLFuzz — LLM-guided baseband fuzzing for MediaTek/Samsung Shannon (KAIST 2025)
- CITesting — Context integrity violation testing for LTE core networks
- Kairos — Timing-induced interaction failure testing
- ASTRA-5G — Automated OTA security testing for 5G SA devices
- certmitm — TLS implementation testing tool
Attack Vectors
Radio Jamming Attacks
From NIST SP 800-187:
- Smart Jamming — Targeted channel interference timed to avoid detection
- Dumb Jamming — Broadband noise across frequency ranges
- UE Interface Jamming — Preventing UE signaling to eNodeB
- eNodeB Interface Jamming — Disrupting base station communications
Overshadowing Attacks (2024-2026)
-
5Gone: Uplink Overshadowing in 5G-SA — Feb 2026
Uplink overshadowing attack transmitting at same time/frequency as victim with higher power. Enables surgical DoS, privacy leaks, and downgrade attacks. Runs on COTS x86 hardware.
-
AdaptOver: Adaptive Overshadowing Attacks — 2022
Adversary can decode, overshadow, and inject arbitrary messages OTA in either direction. Can cause persistent DoS (≥12h) or force IMSI transmission in plaintext. Demonstrated on live LTE/5G-NSA networks at 3.8km range.
5G Security Research
- SNI5GECT: Sniffing and Injecting 5G Traffic — USENIX Security 2025
- Breaking 5G on The Lower Layer — SIB1 spoofing and TA manipulation attacks
- Privacy Attacks on 4G/5G Paging Protocols — NDSS 2019
- European 5G Security in the Wild — 2023
- 5G Threat Modeling Framework
- ENISA 5G Threat Landscape
- 5GReasoner Analysis Framework
- 5G NR Jamming, Spoofing, and Sniffing
- New Privacy Threat on 3G, 4G, and 5G AKA Protocols
- Insecure Connection Bootstrapping in Cellular Networks
- Protecting 4G and 5G Cellular Paging Protocols
- Uncovering Hidden Paths in 5G: Protocol Tunneling — ACM CCS 2025
- 5G Network Slicing Attack Classification — MDPI, July 2025
LTE/4G Security Research
- LTRACK: Stealthy Mobile Phone Tracking — USENIX Security 2022
- Detecting Fake 4G Base Stations in Real Time — Black Hat 2020
- BaseSAFE: Baseband Fuzzing
- LTE Public Warning System Attacks
- Signal Overshadowing Attacks — USENIX Security 2019
- Breaking LTE on Layer Two
- LTE/LTE-A Jamming, Spoofing, and Sniffing
- LTE Protocol Exploits
- Practical Attacks Against Privacy and Availability
- LTE Security Assessment
- LTE Security Disabled: Misconfiguration in Commercial Networks
- All The 4G Modules Could Be Hacked — Black Hat 2019
- Paging Storm Attacks Against 4G/LTE Networks
- Analysis of the LTE Control Plane — IEEE S&P 2019
- Baseband Attacks: Remote Exploitation of Memory Corruptions — WOOT 2012
- Full Chain Baseband Exploits — taszk.io; zero-click RCE in baseband and Android runtime
- Unburdened By What Has Been: Exploiting L2 for Baseband RCE on Samsung Exynos — taszk.io; CVE-2023-41111, CVE-2023-41112
- CITesting: Context Integrity Violations in LTE Core Networks — ACM CCS 2025 (Distinguished Paper)
- New Vulnerabilities in 4G and 5G Cellular Access Network Protocols — WiSec 2019
Conference Talks
Black Hat Asia 2026
-
Qualcomm BootROM Vulnerability (CVE-2026-25262) — Kaspersky ICS CERT
Hardware-level vulnerability in Qualcomm chipsets' Emergency Download Mode (EDL). Unpatchable BootROM flaw allows attackers with physical access to write arbitrary data to memory, potentially gaining full device control. Affects MDM9x07, MDM9x45, MDM9x65, MSM8909, MSM8916, MSM8952, SDX50 series.
Black Hat USA 2025
-
Uncovering 'NASty' 5G Baseband Vulnerabilities through Dependency-Aware Fuzzing
Non-Access Stratum (NAS) layer vulnerability research using dependency-aware fuzzing. Revealed security bypass via "!!FAKE-TESTHARNESS!!" message and challenges with Samsung Shannon baseband symbolic execution. Slides
-
Uncovering Threats and Exposing Vulnerabilities in Next-Gen Cellular RAN
Research on 5G Radio Access Networks transitioning to disaggregated, software-driven O-RAN architectures.
DEF CON 33 (August 2025)
-
Gateways to Chaos: How We Proved Modems Are a Ticking Time Bomb — Chiao-Lin "Steven Meow" Yu, Trend Micro
Over 35 severe flaws in ISP-supplied modems (ADSL, fiber, cable, 4G/5G) rooted in outdated IoT SDKs. Affects power grids, water systems, ATMs globally.
-
Hacking Hotspots: Pre-Auth RCE and Arbitrary SMS on 4G/5G Routers
Reverse-engineering firmware of Tuoshi and KuWFi 4G/5G routers revealing pre-auth RCE and arbitrary SMS injection.
Black Hat USA 2024
-
5G Baseband Vulnerabilities — Penn State University
Researchers disclosed 12 vulnerabilities in 5G basebands from Samsung, MediaTek, and Qualcomm, affecting devices from Google, OPPO, OnePlus, Motorola, and Samsung. Released 5GBaseChecker tool.
DEF CON 32 (August 2024)
-
Economizing Mobile Network Warfare: Budget-Friendly Baseband Fuzzing — Janne Taponen
Making baseband fuzzing accessible with affordable SDR hardware. Covers LLM-assisted protocol parser development and vulnerability discovery across automotive ECUs, payment terminals, and cellular modems.
OffensiveCon 2025
-
No Signal, No Security: Dynamic Baseband Vulnerability Research — Daniel Klischies, David Hirsch
Dynamic approaches to baseband vulnerability research.
-
Mobile Network Attacks: Exploiting Smartphones Through Baseband — Training
Hands-on training covering cellular network fundamentals (2G-5G), baseband OS internals, and vulnerability exploitation techniques.
ACM CCS 2025
-
CITesting: Systematic Testing of Context Integrity Violations in LTE Core Networks — KAIST (Distinguished Paper)
New class of uplink attacks against LTE core networks that work through legitimate base stations — no rogue BTS required. All four tested implementations were vulnerable, including commercial systems from Nokia and Amarisoft.
-
Uncovering Hidden Paths in 5G: Exploiting Protocol Tunneling and Network Boundary Bridging
Demonstrates how attackers can use protocol tunneling to traverse network boundaries and reach isolated 5G components.
IEEE S&P 2025
-
BaseBridge: Bridging Over-the-Air and Emulation Testing for Cellular Baseband Firmware
Framework for cellular baseband firmware security testing combining emulation and OTA approaches.
-
From Control to Chaos: A Comprehensive Formal Analysis of 5G's Access Control — Penn State
USENIX Security 2025
-
SNI5GECT: A Practical Approach to Inject aNRchy into 5G NR — Singapore University of Technology and Design
-
GLaDoS: Location-aware Denial-of-Service of Cellular Networks
USENIX Security 2024
-
Hermes: Unlocking Security Analysis of Cellular Network Protocols
Automatic FSM generation from natural language specifications. Uncovered 3 new vulnerabilities and identified 19 previous attacks.
-
CellularLint: Identifying Inconsistent Behavior in Cellular Network Specifications
LLM-based inconsistency detection in 4G/5G standards.
-
Logic Gone Astray: Security Analysis of 5G Basebands
Control plane protocol analysis framework.
USENIX Security 2023
-
BASECOMP: A Comparative Analysis for Integrity Protection in Cellular Baseband Software
Semi-automated integrity protection analysis using probabilistic inference. Discovered 29 bugs including critical NAS AKA bypass in Samsung. GitHub
Previous Years
- Black Hat USA 2022: Attacks from a New Front Door in 4G and 5G Networks
- Black Hat USA 2021: Over The Air Baseband Exploit — 5G RCE — White Paper
- Black Hat USA 2020: Detecting Fake 4G Base Stations in Real Time
- NSA PLAYSET GSM — DEF CON 22
- VoLTE Phreaking — Ralph Moonen
- RF Exploitation: IoT/OT Hacking with SDR — HITB 2019
- Bye-Bye IMSI Catchers: Security Enhancements in 5G — HITB 2018
- Side Channel Attacks in 4G and 5G — Black Hat Europe 2019
- Dirty Use of USSD Codes in Cellular Networks — TROOPERS 2013, Ravi Borgaonkar
- Hacking LTE Public Warning Systems — HITB 2019
Research Papers
2026
-
5Gone: Uplink Overshadowing Attacks in 5G-SA — ETH Zurich, Feb 2026
SDR-based uplink overshadowing exploiting 3GPP standard deficiencies. E2E latency under 500μs on COTS hardware.
-
Breaking 5G on The Lower Layer — 2026
SIB1 spoofing and Timing Advance manipulation attacks during random access.
-
Kairos: Timing-Induced Interaction Failures in LTE and 5G Core Networks — 2026
Discovered 20 new vulnerabilities and reproduced 34 issues across open-source and commercial cores.
-
Devilray: Adversarial Model Revealing Blind Spots in Fake Base Station Detection — May 2026
Systematic adversarial baseline evaluating 7 FBS detectors across 2,592 configurations.
-
Security Overview and Analysis of 3GPP 5G MAC CE — June 2026
Analysis of 5G NR Medium Access Control protocol specification (3GPP V18.5.0).
-
Semantics Over Syntax: Uncovering Pre-Authentication 5G Baseband Vulnerabilities — April 2026
Automated approach to finding pre-auth vulnerabilities in 5G basebands using semantic analysis.
2025
-
CITesting: Systematic Testing of Context Integrity Violations in LTE Core Networks — ACM CCS 2025 (Distinguished Paper Award)
KAIST's CITesting tool runs thousands of test cases against LTE core implementations, dwarfing the 31-case coverage of prior tooling (LTEFuzz). All four tested implementations contained CIV vulnerabilities.
-
Uncovering Hidden Paths in 5G: Protocol Tunneling and Network Boundary Bridging — ACM CCS 2025
-
5G Network Slicing: Security Challenges, Attack Vectors, and Mitigation Approaches — MDPI, July 2025
-
Starshields for iOS: Navigating the Security Cosmos in Satellite Communication — NDSS 2025
First comprehensive security analysis of Apple's satellite communication features. Researchers reverse-engineered the proprietary protocol, demonstrated restriction bypasses, and built a simulation testbed covering Emergency SOS, Find My, roadside assistance, and iMessage over satellite.
-
RANsacked: A Domain-Informed Approach for Fuzzing LTE and 5G RAN-Core Interfaces — University of Florida / NC State, Jan 2025
119 vulnerabilities, 97 CVEs, across ten implementations. Any one enables city-wide disruption.
-
SNI5GECT: A Practical Approach to Inject aNRchy into 5G NR — USENIX Security 2025
-
GLaDoS: Location-aware Denial-of-Service of Cellular Networks — USENIX Security 2025
-
LLFuzz: LLM-Guided Baseband Firmware Fuzzing — KAIST, July 2025
LLM-guided fuzzing framework targeting MediaTek and Samsung Shannon basebands. Discovered 11 memory corruption vulnerabilities in NAS/RRC message handlers. Uses LLM to generate semantically valid protocol messages for improved coverage.
-
BaseBridge: Bridging Over-the-Air and Emulation Testing for Cellular Baseband Firmware — IEEE S&P 2025
-
From Control to Chaos: Formal Analysis of 5G Access Control — IEEE S&P 2025
2024
-
Hermes: Unlocking Security Analysis of Cellular Network Protocols — USENIX Security 2024
Automatic FSM synthesis from natural language. 81-87% accuracy, 3 new vulnerabilities, 19 previous attacks identified.
-
CellularLint: Identifying Inconsistent Behavior in Cellular Specifications — USENIX Security 2024
-
Logic Gone Astray: Security Analysis of 5G Basebands — USENIX Security 2024
-
ASTRA-5G: Automated Over-the-Air Security Testing for 5G SA Devices — WiSec 2024
-
Catch You Cause I Can: Busting Rogue Base Stations using CellGuard — RAID 2024
-
Survey on 5G Physical Layer Security Threats and Countermeasures — MDPI Sensors 2024
Comprehensive review of PHY-layer attack surface covering eavesdropping, jamming, spoofing, pilot contamination, and SDR-based research frameworks.
-
The Impact of IMSI Catcher Deployments on Cellular Network Security — 2024
2023
-
BASECOMP: A Comparative Analysis for Integrity Protection in Cellular Baseband Software — USENIX Security 2023
Semi-automated integrity protection analysis. Discovered 29 bugs including critical NAS AKA bypass in Samsung.
2019-2022
-
FirmWire: Transparent Dynamic Analysis for Cellular Baseband Firmware — NDSS 2022
-
Privacy Attacks on 4G/5G Paging Protocols — NDSS 2019
-
New Vulnerabilities in 4G and 5G Cellular Access Network Protocols — WiSec 2019
Three new attack classes exploiting unprotected device capability information: identification, bidding-down, and battery drain.
-
AdaptOver: Adaptive Overshadowing Attacks in Cellular Networks — 2022
OTA message injection at 3.8km range. Demonstrated on live LTE/5G-NSA networks.
Equipment and Hardware
Research Equipment Used in "Over The Air Baseband Exploit"
| Component | Purpose | Link |
|---|---|---|
| Ettus USRP B210 | Software Defined Radio | Product Page |
| srsENB | 4G/5G Base Station Software | GitHub |
| Open5GS | 5G Core Network | GitHub |
| sysmo-usim-tool | SIM Programming | Project Page |
| pysim | SIM Analysis Tool | GitHub |
| CoIMS | VoLTE Testing | Play Store |
| Docker Open5GS | Containerized Core | Tutorial |
Detection and Defense
Protection from Stingrays and IMSI Catchers
-
Rayhunter — EFF, 2025
Open-source IMSI catcher detector that runs on affordable Orbic mobile hotspots (~$20-30). Analyzes control traffic in real-time looking for 2G downgrade attempts and unusual IMSI requests. Thousands deployed worldwide with community-contributed packet captures. Documentation — Blog Post
-
CellGuard — SEEMOO Lab, 2024
iOS app that detects rogue base stations by analyzing baseband packets in real-time. Integrates with the Apple Cell Location Database for anomaly detection. Website — Research Paper
-
BaseTrace — SEEMOO Lab
Framework for researching the interface between iPhone's application processor and baseband.
IMSI Catcher Detection and Research
- SeaGlass: City-Wide IMSI-Catcher Detection — UW
- SeaGlass Research Paper — PETS 2017
- Evaluating IMSI Catcher Detectors — Oxford
- IMSI-Catcher Detector (Android)
- Devilray: Adversarial FBS Detection Analysis — May 2026
Security Advisories
Cellular IoT and NB-IoT Security
- NB-IoT Security Analysis Framework — Narrowband IoT security research
- Cat-M1/LTE-M Attack Vectors — GSMA IoT security guidelines
- Monitoring 5G Core Networks Vulnerabilities With eBPF — IEEE Networking Letters 2025
Satellite-Cellular Integration
- Starshields for iOS: Satellite Communication Security — NDSS 2025
- 3GPP Non-Terrestrial Networks (NTN) Security — Official 5G satellite integration specs
- LEO Satellite Cellular Vulnerabilities — Low Earth Orbit security research
Private 5G Network Security
- O-RAN Alliance Security Update 2025 — WG11 security assurance program and AI/ML threat analysis
- O-RAN Security Risks and Vulnerabilities — 60% of risks are DoS/performance degradation; xApp compromise threats
- Open RAN: Attack of the xApps — Trend Micro analysis of Near-RT RIC vulnerabilities
- End-to-End O-RAN Security Architecture — Threat surface analysis including Open Fronthaul
- Private 5G Penetration Testing Guide — Enterprise private network testing
- Campus 5G Security Assessment — NIST private 5G security guidance
- Security Implications of 5G Communication in Industrial Systems — 2024
Network Slicing and Edge Security
- 5G Network Slicing Attack Research — MDPI, July 2025
- Multi-Access Edge Computing (MEC) Vulnerabilities — ETSI MEC security specs
- Network Function Virtualization (NFV) Attacks — Virtual network function security
Automotive and Industrial Cellular
- Security Analysis of LTE Connectivity in Connected Cars: Tesla Case Study — 2025
- V2X Security Research — Vehicle-to-everything communications
- Cellular-V2X Attack Vectors — Automotive cellular security
- BMW Security Assessment using OpenBTS — Keen Lab / Tencent
Forensics and Investigation
- XRY Mobile Forensics — Commercial cellular forensics platform
- Cellebrite UFED — Mobile device extraction tools
- NIST Mobile Forensics Guidelines — NIST SP 800-101r1
Vulnerability Disclosure
- Android Security Bulletins — Regular Android/baseband patches
- Qualcomm Security Bulletins — Snapdragon security updates
- Samsung Mobile Security — Galaxy security research program
- Samsung Semiconductor Security Updates — Shannon baseband CVEs
- Apple Security Research — iOS/baseband security program
SIM Security
SIM Swap Attack Prevention and Detection
- iVerify SIM Swap Detection — Mobile security platform with SIM swap attack detection capabilities
- ML-Based SIM Swap Detection Research — Machine learning approaches to detecting SIM swap fraud patterns
- T-Mobile SIM Protection — Carrier SIM protection features (Account Takeover Protection)
- CTIA SIM Swap Best Practices — Industry guidelines for SIM swap fraud prevention
SIM Vulnerability Research
- Rooting SIM Cards — Black Hat 2013, Karsten Nohl
- SIM Port Hack Case Study
- Cloning 3G/4G SIM Cards With a PC and an Oscilloscope — Black Hat 2015
SS7 and Telecom Infrastructure
SS7 Attack Research
- Bypassing GSMA SS7 Recommendations — Kirill Puzankov
- Attacking SS7 Networks — HES 2010
- SS7: Locate. Track. Manipulate. — 31C3 2014, Tobias Engel; live demonstration of cross-network subscriber tracking
- SS7 Map — P1 Security; map of SS7 exposure across global carriers
- Diameter Vulnerabilities Exposure — GSMA FS.07; official Diameter security guidance for 4G roaming
- GSMA FS.11 SS7 Security — GSMA baseline SS7 network security requirements
SS7/Diameter Testing Tools
- SigPloit — Modular testing framework for SS7, Diameter, GTP, and SIP; covers location tracking, call/SMS interception, and DoS scenarios
- ss7map — Automated SS7 network topology and exposure mapper
- SCTP scanner — Discovers SCTP-based SS7 endpoints on IP networks
Surveillance Technology
Stingray / IMSI Catchers
- DHS Stingray Surveillance — Wired
- Stingray Cost Analysis — Vice
- NYCLU Stingray Information
- EFF: Cell Site Simulators / IMSI Catchers
- WiFi IMSI Catcher — Black Hat Europe 2016
Recent CVEs and Updates
2026 Notable CVEs
- CVE-2026-25262 — Qualcomm BootROM (Sahara protocol) unpatchable vulnerability; affects MDM9x07, MDM9x45, MDM9x65, MSM8909, MSM8916, MSM8952, SDX50 series
- CVE-2026-21385 — Qualcomm Graphics memory corruption; exploited in targeted attacks on Android
- MediaTek March 2026 Bulletin — CVE-2026-20423 through CVE-2026-20445 affecting MT7902, MT7920, MT7921, MT7922, MT7925, MT7927
2024-2025 Notable CVEs
- CVE-2023-24033 (Google Project Zero) — Samsung Exynos baseband: internet-to-baseband RCE via malformed SDP in VoLTE/VoWiFi; no user interaction required. Part of 18 zero-day disclosure affecting Pixel 6/7, Galaxy S22, Vivo, and Samsung wearables
- CVE-2024-55568 — Samsung Exynos baseband heap buffer overflow in SDP parsing; remote code execution via crafted VoLTE packets
- CVE-2024-25073 — Samsung Shannon baseband: pointer not properly checked in Call Control module, leads to DoS
- CVE-2025-58349 — Samsung: incorrect handling of LTE MAC packets with many MAC Control Elements causes baseband crash
- Open5GS CVEs (2024-2025) — Multiple DoS vulnerabilities including NULL pointer dereferences and assertion failures
- RANsacked: 97 CVEs — Affecting Open5GS, Magma, OAI, Athonet, SD-Core, NextEPC, srsRAN
CVE Resources
- NVD CVE Search — Search for cellular-related CVEs
- Google Project Zero — Ongoing mobile security research
- Samsung Security Bulletins — Regular baseband updates
- SIMjacker Research — SIM-based attack evolution
- Free5GC CVEs — OpenCVE tracking
International Research
- ENISA 5G Reports — EU 5G security assessments
- KAIST SysSec Lab — Leading cellular security research group (CITesting, LTEFuzz, LTESniffer, BASECOMP)
- Penn State SyNSec Lab — Syed Rafiul Hussain's group (5GBaseChecker, Hermes, CellularLint)
- Japanese 5G Security Guidelines — Japan national cybersecurity strategy
- ASSET Research Group (Singapore) — 5GHOUL, SNI5GECT research
Training and Education
Professional Training
- OffensiveCon: Mobile Network Attacks Training — Hands-on baseband exploitation (2G-5G)
- SANS Mobile Security — Professional mobile security courses
- Offensive Security Mobile Testing — Advanced mobile penetration testing
- PentHertz Training — RF and wireless security training
Lab Environments
- Open5GS + srsRAN Lab Setup — Complete 5G SA config with ZeroMQ UE/RAN
- End-to-End Open5GS-srsRAN Guide — Deployment guide for Ubuntu 22.04
- 5G SA Lab Setup Tutorial — Step-by-step srsRAN + Open5GS guide
- OpenAirInterface Lab Setup — Open-source 5G lab environment
- DragonOS — Pre-configured SDR Linux distribution; latest is Noble (24.04)
- 5G Security Datasets — PCAP, CSV, and AMF logs for flooding/fuzzing/replay attacks on Open5GS, OAI, Amarisoft
- GNU Radio / SDR University Courses — SDR educational materials
- VET5G: Virtual Testbed for 5G Security — OpenAirInterface + Android emulator testbed
Vendor-Specific Research
- Ericsson Security Research
- Nokia Bell Labs Security
- Qualcomm Security Bulletins
- MediaTek Product Security
- Samsung Shannon Baseband Research
- Google Project Zero: 18 Exynos Zero-Days (2023) — CVE-2023-24033 and 17 others; 4 RCE without user interaction via VoLTE/VoWiFi
- Google Project Zero: Exynos Baseband CVE-2024-55568 — Heap buffer overflow in Samsung Exynos baseband allowing remote code execution
Roaming and Interconnect Security
- GRX/IPX Security Research — GSMA roaming security
- Diameter Protocol Security — 4G/5G signaling security
- GSMA FS.19 IPX Security — Security requirements for IPX providers handling roaming traffic
- Roaming Attacks via Diameter — P1 Security analysis of Diameter-based roaming attack surface
- GTP Vulnerabilities in 4G/5G Roaming — GTP-C and GTP-U attack surface at the roaming interface
- AdaptiveMobile SS7 Firewall Research — Carrier-grade SS7/Diameter firewall bypass techniques
Resources
GitHub Collections
- Cellular-Security-Papers — Comprehensive collection of academic papers, tools, and talks
- Awesome-Cellular-Hacking — This repository
- Firmware-Analysis-Papers — Baseband and firmware security papers
- 5GSEC — 5G security research organization
Development and Analysis Tools
- RTL-SDR Community — SDR resources and tutorials
- MCC-MNC Database — Mobile Country/Network Code reference
- RFSec-ToolKit — RF security testing tools
- cellularsecurity.org — Community resource for cellular security research
Research Collections
- RF Security Documentation
- USENIX Security Papers — Security conference proceedings
- ACM Digital Library — ACM research papers
- IEEE Xplore — IEEE research database
Legal and Regulatory
- FCC Equipment Authorization Rules — US cellular equipment regulations
- CISA 5G Security Guidance — US critical infrastructure guidance
- NIST 5G Cybersecurity — NIST cellular security frameworks
Video Tutorials
- DragonOS FocalX Cellular Security Research w/ LTESniffer (Part 1) — srsRAN, LimeSDR, B205mini setup
- DragonOS FocalX Cellular Security Research + IMSI Capture w/ LTESniffer (Part 3) — X310, srsRAN advanced config
- RTL-SDR SDR and RF Videos from DEF CON 32 — Collection of RF/cellular talks
Additional Reading
- Analyzing GSM Downlink with USRP
- AT&T Microcell Analysis
- LTE Recon — DefCon 23
- LTE Security Guide — NIST SP 800-187
- LTE Pwnage: Core Network Elements — HITB 2013
Community
Mailing Lists and Forums
- Osmocom Mailing Lists — Active developer and user lists for OpenBTS, OsmocomBB, srsRAN topics
- srsRAN Discussions — GitHub Discussions for the srsRAN Project
- OpenAirInterface Forum — OAI issue tracker and community support
- Reddit r/RTLSDR — Active SDR community covering cellular scanning and analysis
- Reddit r/cellmapper — Cell tower mapping and analysis community
IRC and Chat
- Osmocom IRC — #osmocom on libera.chat; real-time support for Osmocom tools
- DEF CON RF Village — Annual RF hacking community track at DEF CON
Notable Researchers and Organizations to Follow
| Name/Organization | Focus Area | Link |
|---|---|---|
| Syed Rafiul Hussain | 5G/LTE protocol security, baseband fuzzing | Website |
| Imtiaz Karim | 5GReasoner, LTE noncompliance, cellular formal verification | Website |
| KAIST SysSec Lab | LTE/5G core network security | Website |
| SEEMOO Lab (TU Darmstadt) | iOS baseband, IMSI catcher detection | GitHub |
| ASSET Research Group | 5G NR fuzzing (5GHOUL, SNI5GECT) | Website |
| cemaxecuter | DragonOS, WarDragon, Ransack cellular survey tools | Twitter / Website |
| taszk.io | Samsung/MediaTek baseband exploits, full-chain RCE | Website |
| Google Project Zero | Baseband vulnerability research, Exynos zero-days | Blog |
| PentHertz | RF/wireless security pentesting | |
| P1 Security | SS7/Diameter security | Website |
| EFF | Surveillance tech, Rayhunter, Crocodile Hunter | Website |
Conferences and Competitions
- DEF CON — RF Village, Wireless Village, and main track cellular talks
- Black Hat USA/Europe — Regular cellular/baseband research presentations
- OffensiveCon — Baseband exploitation talks and training
- Pwn2Own Ireland — Mobile-focused; $100K for baseband RCE exploits
- CanSecWest — Baseband and mobile security research presentations
- WiSec — ACM Conference on Security and Privacy in Wireless and Mobile Networks
- IEEE S&P / CCS / USENIX Security — Top-tier academic venue for cellular security papers
- HITB — Regular telecom security talks
- NDSS — Network security including FutureG workshop on 5G/6G
Contributing
Fork the repo, add resources with descriptions, verify links are active, and submit a pull request with context on what was added.
Legal Notice
This repository is for educational and research purposes only. Users are responsible for complying with all applicable laws and regulations. The maintainers do not endorse or encourage illegal activities.
Last Updated: August 2026 Maintainer: @W00t3k
Broken links or new resources? Open an issue or submit a PR.