Skip to content

IMSI Catcher

Definition

A rogue base station (commercial: Stingray, Hailstorm, KingFisher; research: USRP plus srsRAN or YateBTS) that impersonates a cellular cell, forces nearby phones to attach, and logs the IMSI and IMEI. Often paired with a forced downgrade from 4G or 5G to 2G GSM.

Device type
Rogue base station that impersonates a legitimate cellular cell
What it captures
IMSI (International Mobile Subscriber Identity) and IMEI (device identifier) from nearby phones
Common tactic
Often paired with a forced downgrade from 4G/5G to 2G GSM for easier exploitation

Common questions

What does an IMSI catcher actually do?+

An IMSI catcher is a rogue base station that impersonates a real cellular cell. It forces nearby phones to connect to it, allowing it to capture the phone's IMSI (International Mobile Subscriber Identity) and IMEI (device identifier). This happens without the user's knowledge or consent.

Why would someone force a phone to downgrade from 4G or 5G to 2G?+

Older 2G GSM networks are more vulnerable to interception and IMSI capture than newer standards. By forcing a downgrade, attackers can exploit weaker security in the older protocol, making it easier to extract and log the target device's identifiers.

What are some known IMSI catcher devices?+

Commercial versions include Stingray, Hailstorm, and KingFisher. Researchers can also build them using general-purpose radio equipment (a USRP) combined with open-source cellular network software like srsRAN or YateBTS.

Related terms

4-Way Handshake
The WPA/WPA2 key-establishment exchange between client and AP. Captured frames let an offline dictionary attack recover a weak PSK. WPA3 replaces this...
BSSID / ESSID
BSSID is the MAC address of the access point (or virtual AP). ESSID is the human-readable network name broadcast in beacons. Multiple...
CLI Spoofing
Caller Line Identification spoofing: the caller forges the Calling Party Number sent in the SS7 IAM or SIP From header so the...
Evil Twin
A rogue AP broadcasting the same ESSID as a legitimate network at a stronger signal, so clients with cached profiles auto-associate. Often...
KRACK
Key Reinstallation Attack, CVE-2017-13077, disclosed by Mathy Vanhoef in 2017. By replaying message 3 of the 4-way handshake, the client is forced...
Phreaking
Tone-based exploitation of the public switched telephone network, pioneered in the 1960s and 1970s. The 2600 Hz tone, generated by a toy...
PMKID Attack
A 2018 technique by Jens Steube (hashcat author) that derives the Pairwise Master Key Identifier from a single EAPOL frame the AP...
QRJacking
Physical replacement or overlay of a legitimate merchant QR (typically a UPI QR at a shop counter) with a fraudster's QR pointing...
SIM Swap
Fraud pattern where the attacker convinces the telco to port the victim's MSISDN to a SIM the attacker holds. Once active, the...
TRAI 24-Hour Cool-Off
Telecom Regulatory Authority of India directive (2018 and tightened thereafter) requiring that after a SIM swap the new SIM cannot be used...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.