IMSI Catcher
Definition
A rogue base station (commercial: Stingray, Hailstorm, KingFisher; research: USRP plus srsRAN or YateBTS) that impersonates a cellular cell, forces nearby phones to attach, and logs the IMSI and IMEI. Often paired with a forced downgrade from 4G or 5G to 2G GSM.
- Device type
- Rogue base station that impersonates a legitimate cellular cell
- What it captures
- IMSI (International Mobile Subscriber Identity) and IMEI (device identifier) from nearby phones
- Common tactic
- Often paired with a forced downgrade from 4G/5G to 2G GSM for easier exploitation
Common questions
What does an IMSI catcher actually do?+
An IMSI catcher is a rogue base station that impersonates a real cellular cell. It forces nearby phones to connect to it, allowing it to capture the phone's IMSI (International Mobile Subscriber Identity) and IMEI (device identifier). This happens without the user's knowledge or consent.
Why would someone force a phone to downgrade from 4G or 5G to 2G?+
Older 2G GSM networks are more vulnerable to interception and IMSI capture than newer standards. By forcing a downgrade, attackers can exploit weaker security in the older protocol, making it easier to extract and log the target device's identifiers.
What are some known IMSI catcher devices?+
Commercial versions include Stingray, Hailstorm, and KingFisher. Researchers can also build them using general-purpose radio equipment (a USRP) combined with open-source cellular network software like srsRAN or YateBTS.
Related terms
- 4-Way Handshake
- The WPA/WPA2 key-establishment exchange between client and AP. Captured frames let an offline dictionary attack recover a weak PSK. WPA3 replaces this...
- BSSID / ESSID
- BSSID is the MAC address of the access point (or virtual AP). ESSID is the human-readable network name broadcast in beacons. Multiple...
- CLI Spoofing
- Caller Line Identification spoofing: the caller forges the Calling Party Number sent in the SS7 IAM or SIP From header so the...
- Evil Twin
- A rogue AP broadcasting the same ESSID as a legitimate network at a stronger signal, so clients with cached profiles auto-associate. Often...
- KRACK
- Key Reinstallation Attack, CVE-2017-13077, disclosed by Mathy Vanhoef in 2017. By replaying message 3 of the 4-way handshake, the client is forced...
- Phreaking
- Tone-based exploitation of the public switched telephone network, pioneered in the 1960s and 1970s. The 2600 Hz tone, generated by a toy...
- PMKID Attack
- A 2018 technique by Jens Steube (hashcat author) that derives the Pairwise Master Key Identifier from a single EAPOL frame the AP...
- QRJacking
- Physical replacement or overlay of a legitimate merchant QR (typically a UPI QR at a shop counter) with a fraudster's QR pointing...
- SIM Swap
- Fraud pattern where the attacker convinces the telco to port the victim's MSISDN to a SIM the attacker holds. Once active, the...
- TRAI 24-Hour Cool-Off
- Telecom Regulatory Authority of India directive (2018 and tightened thereafter) requiring that after a SIM swap the new SIM cannot be used...
Explained in these topics
- Wireless and Mobile Network Attacks: Phreaking, SIM Swap, NFC and QRA rogue base station (commercial: Stingray, Hailstorm, KingFisher; research: USRP plus srsRAN or YateBTS) that impersonates a cellular cell, forces nearby phon...
- Wireless Network Attacks: WEP, WPA, WPA2, WPA3 and Rogue Access PointsA device (commercially named Stingray, KingFisher, or built from a USRP plus open-source code) that impersonates a cellular base station and forces nearby phon...