Awesome Cellular Hacking

August 28, 2026 · View on GitHub

A comprehensive curated list of resources for 2G/3G/4G/5G cellular security research and analysis

This repository consolidates community knowledge in the cellular security space, including exploits, research papers, tools, and educational resources. The goal is to preserve and organize important security research that might otherwise become difficult to find.

Disclaimer: This information is intended for educational and defensive security research purposes only. Use responsibly and in compliance with applicable laws and regulations.

Table of Contents


Getting Started

New to cellular security research? This section outlines the recommended path for building foundational skills.

Skill Levels

Beginner (passive listening only)

  • Hardware: RTL-SDR V3 or V4 ($35-$40), a laptop running Linux
  • Software: GNU Radio, GQRX, gr-gsm
  • First project: Scan and decode GSM frames passively using gr-gsm and Wireshark
  • Reading: NIST SP 800-187 LTE Security Guide

Intermediate (active research lab)

  • Hardware: HackRF One or LimeSDR Mini ($139-$350), programmable SIM cards (sysmoUSIM), a spare Android device
  • Software: srsRAN 4G, Open5GS or Free5GC, OsmocomBB
  • First project: Build a private LTE network in a Faraday cage and connect a test device
  • Reading: srsRAN documentation, Open5GS tutorials

Advanced (protocol fuzzing and baseband research)

  • Hardware: USRP B210 or BladeRF 2.0, multiple test devices
  • Software: 5GBaseChecker, LTEFuzz, BaseBridge, SigPloit, FirmWire, 5GHOUL
  • Focus areas: Baseband fuzzing, RAN-Core interface testing, SS7/Diameter signaling

Lab Setup Checklist

  • Linux host (Ubuntu 22.04 or 24.04 recommended)
  • UHD drivers installed and device recognized (uhd_find_devices)
  • Faraday cage or RF shielding for active transmissions
  • Programmable SIM cards (sysmoUSIM-SJA2 or similar)
  • Dedicated test devices (not your daily driver)
  • Isolated network environment (no production network access)

Key Concepts to Understand First


Rogue Base Stations

GSM/CDMA Traffic Impersonation and Interception


Recent Updates (2024-2026)

New Research (2025-2026)

New Research (2024)

Base Station Software and Tools (Updated)

  • OpenBTS 2024 Reloaded — Updated for modern UHD drivers and Ubuntu 22.04/24.04
  • OpenAirInterface (OAI) — Complete 3GPP Release-15+ implementation with active 5G development
  • LimeNET CrowdCell — Network-in-a-box with integrated LimeSDR for small cell deployments
  • Amarisoft LTEENB/gNB — Professional-grade LTE/5G NR base station software
  • DragonOS — Debian/Lubuntu-based SDR distro with cellular tools pre-installed; supports RTL-SDR, HackRF, LimeSDR, BladeRF; latest release is DragonOS Noble (24.04). Website
  • WarDragon — Passive RF sensor platform with AI-enhanced cellular survey capabilities; integrates with TAK; includes Ransack for multi-RAT survey
  • Magma Core Network — Meta's distributed packet core, now under the Linux Foundation
  • 5GBaseChecker — Automated 5G baseband vulnerability detection tool
  • Ransack — Multi-RAT cellular survey/recon platform; unifies LTE/5G NR/GSM/NB-IoT observations from SDRs, Qualcomm phones, and Rayhunter into SQLite with REST API
  • 5GHOUL — 5G NR fuzzing and attack framework targeting Qualcomm/MediaTek

Software and Tools

Base Station Software

SoftwareDescriptionLink
OpenBTS (2024 Reloaded)Updated Linux SDR-based GSM air interface for modern systemsGitHub
OpenBTS (Original)Range Networks implementationSourceForge
YateBTSGSM/GPRS radio access network implementationWebsite
srsRAN ProjectOpen-source 5G O-RAN CU/DU software suiteGitHub
srsRAN 4GOpen-source 4G software radio suiteGitHub
OpenAirInterfaceComplete 4G/5G protocol stackWebsite
Free5GCOpen-source 5G core network implementationGitHub
Open5GSOpen-source 5G core and EPC implementationGitHub
KamailioOpen-source SIP server used in IMS/VoLTE labsWebsite

Configuration Guides

Analysis Tools

ToolDescriptionLink
RansackMulti-RAT cellular survey platform for DragonOS; merges LTE/5G NR/GSM/NB-IoT into unified DB; orchestrates srsRAN, LTESniffer, FALCON, RayhunterGitHub
RayhunterEFF's IMSI catcher detector for Orbic hotspots; detects 2G downgrades and suspicious requestsGitHub
5GBaseCheckerAutomated 5G baseband vulnerability detection (Penn State)GitHub
5GHOUL5G NR attacks against Qualcomm/MediaTek with stateful fuzzerGitHub
FirmWireFull-system baseband firmware emulation for fuzzing/debuggingGitHub
BaseBridgeBridges OTA and emulation testing for baseband firmwareGitHub
LTE-Cell-ScannerLTE cell detection and analysisGitHub
gr-gsmGSM analysis with GNU RadioGitHub
IMSI-Catcher DetectorAndroid app for detecting IMSI catchersGitHub
CellGuardiOS app detecting rogue base stations via baseband analysisGitHub
QCSuperCapture 2G-4G traffic using Qualcomm phonesP1 Security
FALCON LTEFast analysis of LTE control channels in real-timeGitHub
KalibrateGSM base station scanner and frequency calibrationGitHub
LTE SnifferOpen-source LTE downlink/uplink eavesdropperGitHub
OsmocomBBFree firmware for mobile phone baseband processorsOsmocom
ModmobmapMobile network mappingGitHub
ModmobjamMobile jamming research toolGitHub
CITestingContext integrity violation testing for LTE core networksACM DL
SigPloitSS7/Diameter/GTP/SIP signaling security testing frameworkGitHub
LTEFuzzLTE protocol fuzzer (KAIST)GitHub
LLFuzzLLM-guided baseband firmware fuzzing for MediaTek/Samsung ShannonPaper
Crocodile HunterEFF tool for detecting rogue cell towers by wardrivingGitHub
SCATSignaling Collection and Analysis Tool for Qualcomm/SamsungGitHub
HermesFSM synthesis from natural language specificationsGitHub
CellularLintInconsistency detection in 4G/5G standardsGitHub
5GReasonerProperty-directed formal verification of 5G control-plane protocolsPaper
DoLTEstDownlink negative testing framework for LTE devices; 1,848 test casesPaper
ProCheckerFSM extraction + model checking for 4G LTE implementationsPaper
LTEInspectorProperty-driven adversarial model-based testing for 4G LTEPaper
BASECOMPComparative analysis for baseband integrity protectionGitHub
BaseTraceFramework for iPhone baseband interface researchGitHub
ss7mapSS7 network exposure mappingP1 Security
Osmocom SuiteComplete open-source GSM/GPRS stackOsmocom

Hardware Setup

USRP Installation on Linux

# Add Ettus Research repository
sudo add-apt-repository ppa:ettusresearch/uhd
sudo apt-get update

# Install UHD drivers and tools
sudo apt-get install libuhd-dev libuhd003 uhd-host

# Find connected devices
uhd_find_devices

# Download firmware images
cd /usr/lib/uhd/utils/
./uhd_images_downloader.py

# Test device connection
sudo uhd_usrp_probe

SDR Hardware Options

HardwareFrequency RangeBandwidthPrice RangeUse CaseLink
Ettus Research (USRP)
USRP B21070 MHz - 6 GHz61.44 MHz$2,100Professional development, 2x2 MIMOEttus
USRP B200mini70 MHz - 6 GHz61.44 MHz$775Compact USRP B-seriesEttus
USRP N210DC - 6 GHz25 MHz$1,700High-performance networked SDREttus
USRP N3201 MHz - 6 GHz200 MHz$8,000Networked 2x2 MIMOEttus
USRP X310DC - 6 GHz160 MHz$6,000High-performance desktop/rackEttus
USRP X4101 MHz - 7.2 GHz400 MHz$15,000Latest high-performance 4x4 MIMOEttus
USRP X44030 MHz - 4 GHz1.6 GHz$25,000+Latest 8x8 MIMO RFSoC platformEttus
USRP E32070 MHz - 6 GHz56 MHz$4,000Embedded 2x2 MIMO SDREttus
Nuand (BladeRF)
BladeRF 2.0 xA447 MHz - 6 GHz61.44 MHz$420Budget 2x2 MIMO developmentNuand
BladeRF 2.0 xA947 MHz - 6 GHz61.44 MHz$720High FPGA resources, 2x2 MIMONuand
BladeRF x40 (Legacy)300 MHz - 3.8 GHz40 MHz$400Entry-level legacy modelNuand
Great Scott Gadgets
HackRF One1 MHz - 6 GHz20 MHz$350Budget TX/RX developmentGSG
YARD Stick One300-348, 391-464, 782-928 MHz2.5 MHz$110Sub-GHz IoT frequenciesGSG
Lime Microsystems
LimeSDR USB100 kHz - 3.8 GHz61.44 MHz$289Open-source 2x2 MIMOLime Micro
LimeSDR Mini10 MHz - 3.5 GHz30.72 MHz$139Compact LimeSDR variantLime Micro
LimeSDR Mini 2.010 MHz - 3.5 GHz30.72 MHz$169Updated with ECP5 FPGALime Micro
LimeSDR X3Various bandsUp to 61.44 MHz$3,000+Professional 3x transceiver PCIeLime Micro
Analog Devices
PlutoSDR325 MHz - 3.8 GHz20 MHz$150Education and learning platformAnalog Devices
RTL-SDR Blog
RTL-SDR V3500 kHz - 1.75 GHz3.2 MHz$35Ultra-budget RX-only scannerRTL-SDR
RTL-SDR V4500 kHz - 1.75 GHz3.2 MHz$40Latest with R828D tunerRTL-SDR
Airspy
Airspy R224 MHz - 1.8 GHz10 MHz$200High-performance VHF/UHF scannerAirspy
Airspy Mini24 MHz - 1.8 GHz6 MHz$99Compact Airspy in dongle formatAirspy
Airspy HF+ Discovery9 kHz - 31 MHz, 60-260 MHz768 kHz$169Dedicated HF receptionAirspy
SDRplay
RSP1A1 kHz - 2 GHz10 MHz$119Wideband general purposeSDRplay
RSPdx1 kHz - 2 GHz10 MHz$299Professional features, dual antennaSDRplay
Red Pitaya
STEMlab 125-14DC - 60 MHz50 MHz$600HF transceiver, lab instrumentRed Pitaya
STEMlab 122-16DC - 50 MHzVariable$625High-resolution HF SDR/scopeRed Pitaya

Common SDR Issues and Troubleshooting

IssuePossible Causes
Device not detectedImproper firmware, USB connection issues
Poor signal qualityIncorrect antennas, wrong frequency configuration
Connection failuresWrong SIM, incorrect MCC/MNC codes
Performance issuesVirtualized platform limitations, wrong SDR firmware

Testing and Research Methodologies

Modern Baseband Fuzzing (2024-2026)

  • SNI5GECT: Practical 5G Traffic Injection — USENIX Security 2025

    Sniff and inject 5G messages without rogue base stations or jamming. Demonstrated 4G downgrade attacks within 20 meters of victim. GitHub

  • "NASty" 5G Baseband Vulnerabilities through Dependency-Aware Fuzzing — Black Hat USA 2025

    Targeting Non-Access Stratum (NAS) layer vulnerabilities using dependency-aware fuzzing. Discovered security bypass using "!!FAKE-TESTHARNESS!!" message. Symbolic execution challenges with Samsung Shannon basebands requiring TB-level memory.

  • Budget-Friendly Baseband Fuzzing Setup — DefCon 32, Janne Taponen

    Covers building cost-effective baseband fuzzing rigs using SDRs, using LLMs to accelerate protocol parser development, and testing automotive ECUs, payment terminals, and mobile devices.

  • RANsacked Fuzzing Framework — University of Florida / NC State, ACM CCS 2024

    Domain-informed fuzzing approach targeting RAN-Core interfaces. Discovered 119 vulnerabilities across ten network implementations.

  • BaseBridge — IEEE S&P 2025

    Framework that bridges over-the-air and emulation-based testing for cellular baseband firmware. Extends FirmWire.

  • FirmWire — NDSS 2022

    Full-system baseband firmware emulation platform for Samsung and MediaTek. Discovered 8 remote memory corruptions including 3 pre-authentication RCE vulnerabilities.

Vulnerability Research Tools

  • 5GBaseChecker — Automated 5G baseband vulnerability detection
  • 5GHOUL — Stateful 5G NR fuzzer with OTA attack capabilities
  • LLFuzz — LLM-guided baseband fuzzing for MediaTek/Samsung Shannon (KAIST 2025)
  • CITesting — Context integrity violation testing for LTE core networks
  • Kairos — Timing-induced interaction failure testing
  • ASTRA-5G — Automated OTA security testing for 5G SA devices
  • certmitm — TLS implementation testing tool

Attack Vectors

Radio Jamming Attacks

From NIST SP 800-187:

  • Smart Jamming — Targeted channel interference timed to avoid detection
  • Dumb Jamming — Broadband noise across frequency ranges
  • UE Interface Jamming — Preventing UE signaling to eNodeB
  • eNodeB Interface Jamming — Disrupting base station communications

Overshadowing Attacks (2024-2026)

  • 5Gone: Uplink Overshadowing in 5G-SA — Feb 2026

    Uplink overshadowing attack transmitting at same time/frequency as victim with higher power. Enables surgical DoS, privacy leaks, and downgrade attacks. Runs on COTS x86 hardware.

  • AdaptOver: Adaptive Overshadowing Attacks — 2022

    Adversary can decode, overshadow, and inject arbitrary messages OTA in either direction. Can cause persistent DoS (≥12h) or force IMSI transmission in plaintext. Demonstrated on live LTE/5G-NSA networks at 3.8km range.

5G Security Research

LTE/4G Security Research


Conference Talks

Black Hat Asia 2026

  • Qualcomm BootROM Vulnerability (CVE-2026-25262) — Kaspersky ICS CERT

    Hardware-level vulnerability in Qualcomm chipsets' Emergency Download Mode (EDL). Unpatchable BootROM flaw allows attackers with physical access to write arbitrary data to memory, potentially gaining full device control. Affects MDM9x07, MDM9x45, MDM9x65, MSM8909, MSM8916, MSM8952, SDX50 series.

Black Hat USA 2025

DEF CON 33 (August 2025)

Black Hat USA 2024

DEF CON 32 (August 2024)

OffensiveCon 2025

ACM CCS 2025

IEEE S&P 2025

USENIX Security 2025

USENIX Security 2024

USENIX Security 2023

Previous Years


Research Papers

2026

2025

2024

2023

2019-2022


Equipment and Hardware

Research Equipment Used in "Over The Air Baseband Exploit"

ComponentPurposeLink
Ettus USRP B210Software Defined RadioProduct Page
srsENB4G/5G Base Station SoftwareGitHub
Open5GS5G Core NetworkGitHub
sysmo-usim-toolSIM ProgrammingProject Page
pysimSIM Analysis ToolGitHub
CoIMSVoLTE TestingPlay Store
Docker Open5GSContainerized CoreTutorial

Detection and Defense

Protection from Stingrays and IMSI Catchers

  • Rayhunter — EFF, 2025

    Open-source IMSI catcher detector that runs on affordable Orbic mobile hotspots (~$20-30). Analyzes control traffic in real-time looking for 2G downgrade attempts and unusual IMSI requests. Thousands deployed worldwide with community-contributed packet captures. DocumentationBlog Post

  • CellGuard — SEEMOO Lab, 2024

    iOS app that detects rogue base stations by analyzing baseband packets in real-time. Integrates with the Apple Cell Location Database for anomaly detection. WebsiteResearch Paper

  • BaseTrace — SEEMOO Lab

    Framework for researching the interface between iPhone's application processor and baseband.

IMSI Catcher Detection and Research

Security Advisories


Cellular IoT and NB-IoT Security


Satellite-Cellular Integration


Private 5G Network Security


Network Slicing and Edge Security


Automotive and Industrial Cellular


Forensics and Investigation


Vulnerability Disclosure


SIM Security

SIM Swap Attack Prevention and Detection

SIM Vulnerability Research


SS7 and Telecom Infrastructure

SS7 Attack Research

SS7/Diameter Testing Tools

  • SigPloit — Modular testing framework for SS7, Diameter, GTP, and SIP; covers location tracking, call/SMS interception, and DoS scenarios
  • ss7map — Automated SS7 network topology and exposure mapper
  • SCTP scanner — Discovers SCTP-based SS7 endpoints on IP networks

Surveillance Technology

Stingray / IMSI Catchers


Recent CVEs and Updates

2026 Notable CVEs

  • CVE-2026-25262 — Qualcomm BootROM (Sahara protocol) unpatchable vulnerability; affects MDM9x07, MDM9x45, MDM9x65, MSM8909, MSM8916, MSM8952, SDX50 series
  • CVE-2026-21385 — Qualcomm Graphics memory corruption; exploited in targeted attacks on Android
  • MediaTek March 2026 Bulletin — CVE-2026-20423 through CVE-2026-20445 affecting MT7902, MT7920, MT7921, MT7922, MT7925, MT7927

2024-2025 Notable CVEs

  • CVE-2023-24033 (Google Project Zero) — Samsung Exynos baseband: internet-to-baseband RCE via malformed SDP in VoLTE/VoWiFi; no user interaction required. Part of 18 zero-day disclosure affecting Pixel 6/7, Galaxy S22, Vivo, and Samsung wearables
  • CVE-2024-55568 — Samsung Exynos baseband heap buffer overflow in SDP parsing; remote code execution via crafted VoLTE packets
  • CVE-2024-25073 — Samsung Shannon baseband: pointer not properly checked in Call Control module, leads to DoS
  • CVE-2025-58349 — Samsung: incorrect handling of LTE MAC packets with many MAC Control Elements causes baseband crash
  • Open5GS CVEs (2024-2025) — Multiple DoS vulnerabilities including NULL pointer dereferences and assertion failures
  • RANsacked: 97 CVEs — Affecting Open5GS, Magma, OAI, Athonet, SD-Core, NextEPC, srsRAN

CVE Resources


International Research


Training and Education

Professional Training

Lab Environments


Vendor-Specific Research


Roaming and Interconnect Security


Resources

GitHub Collections

Development and Analysis Tools

Research Collections

Video Tutorials

Additional Reading


Community

Mailing Lists and Forums

IRC and Chat

  • Osmocom IRC — #osmocom on libera.chat; real-time support for Osmocom tools
  • DEF CON RF Village — Annual RF hacking community track at DEF CON

Notable Researchers and Organizations to Follow

Name/OrganizationFocus AreaLink
Syed Rafiul Hussain5G/LTE protocol security, baseband fuzzingWebsite
Imtiaz Karim5GReasoner, LTE noncompliance, cellular formal verificationWebsite
KAIST SysSec LabLTE/5G core network securityWebsite
SEEMOO Lab (TU Darmstadt)iOS baseband, IMSI catcher detectionGitHub
ASSET Research Group5G NR fuzzing (5GHOUL, SNI5GECT)Website
cemaxecuterDragonOS, WarDragon, Ransack cellular survey toolsTwitter / Website
taszk.ioSamsung/MediaTek baseband exploits, full-chain RCEWebsite
Google Project ZeroBaseband vulnerability research, Exynos zero-daysBlog
PentHertzRF/wireless security pentestingTwitter
P1 SecuritySS7/Diameter securityWebsite
EFFSurveillance tech, Rayhunter, Crocodile HunterWebsite

Conferences and Competitions

  • DEF CON — RF Village, Wireless Village, and main track cellular talks
  • Black Hat USA/Europe — Regular cellular/baseband research presentations
  • OffensiveCon — Baseband exploitation talks and training
  • Pwn2Own Ireland — Mobile-focused; $100K for baseband RCE exploits
  • CanSecWest — Baseband and mobile security research presentations
  • WiSec — ACM Conference on Security and Privacy in Wireless and Mobile Networks
  • IEEE S&P / CCS / USENIX Security — Top-tier academic venue for cellular security papers
  • HITB — Regular telecom security talks
  • NDSS — Network security including FutureG workshop on 5G/6G

Contributing

Fork the repo, add resources with descriptions, verify links are active, and submit a pull request with context on what was added.

This repository is for educational and research purposes only. Users are responsible for complying with all applicable laws and regulations. The maintainers do not endorse or encourage illegal activities.


Last Updated: August 2026 Maintainer: @W00t3k

Broken links or new resources? Open an issue or submit a PR.