{"id":6078,"url":"https://github.com/W00t3k/Awesome-Cellular-Hacking","name":"Awesome-Cellular-Hacking","description":"Awesome-Cellular-Hacking","projects_count":377,"last_synced_at":"2026-09-01T05:00:33.786Z","repository":{"id":37548476,"uuid":"187701900","full_name":"W00t3k/Awesome-Cellular-Hacking","owner":"W00t3k","description":"Awesome-Cellular-Hacking","archived":false,"fork":false,"pushed_at":"2026-03-21T11:14:33.000Z","size":35257,"stargazers_count":3990,"open_issues_count":2,"forks_count":672,"subscribers_count":182,"default_branch":"master","last_synced_at":"2026-08-23T01:10:24.590Z","etag":null,"topics":["eviltwin","gsm","gsm-network","hacking","lte","lte-evil-twin","rogue-bts","sdr"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/W00t3k.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2019-05-20T19:34:31.000Z","updated_at":"2026-08-22T05:28:10.000Z","dependencies_parsed_at":"2022-07-12T16:22:39.478Z","dependency_job_id":"6f67b9f8-75a7-4b86-aa74-dee1c9b171e2","html_url":"https://github.com/W00t3k/Awesome-Cellular-Hacking","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/W00t3k/Awesome-Cellular-Hacking","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/W00t3k%2FAwesome-Cellular-Hacking","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/W00t3k%2FAwesome-Cellular-Hacking/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/W00t3k%2FAwesome-Cellular-Hacking/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/W00t3k%2FAwesome-Cellular-Hacking/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/W00t3k","download_url":"https://codeload.github.com/W00t3k/Awesome-Cellular-Hacking/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/W00t3k%2FAwesome-Cellular-Hacking/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":37011263,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"online","status_checked_at":"2026-09-01T02:00:05.433Z","response_time":53,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"created_at":"2024-01-07T03:36:00.986Z","updated_at":"2026-09-01T05:00:33.786Z","primary_language":null,"list_of_lists":false,"displayable":true,"categories":["🔧 Hardware Setup","🆕 Recent Updates (2024-2025)","🌐 Network Slicing \u0026 Edge Security","Resources","🎤 Conference Talks","🛰️ Satellite-Cellular Integration","Community","🆕 Recent CVEs \u0026 Updates","🏢 Private 5G Network Security","CERT/Media Alerts","🏗️ Rogue Base Stations","Rogue BTS \u0026 CDMA/GSM Traffic Impersonation and Interception","🛠️ Software \u0026 Tools","📊 Equipment \u0026 Hardware","[JAMMING SPECIFC ATTACKS](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-187.pdf)","🛡️ Detection \u0026 Defense","5G Cellular Attacks","5G Cellular Attacks (Soon to be updated)","⚔️ Attack Vectors","4G/LTE Cellular Attacks","SIM Specific Attacks","SS7/Telecom Specific","Misc","SS7 and Telecom Infrastructure","🔗 Resources","🎓 Training \u0026 Education","🚨 Vulnerability Disclosure","Recent Updates (2024-2026)","🌍 International Research","Software and Tools","Training and Education","📚 Research Papers","🔬 Testing \u0026 Research Methodologies","📚 Additional Reading","📱 Cellular IoT \u0026 NB-IoT Security","🚗 Automotive \u0026 Industrial Cellular","🔍 Forensics \u0026 Investigation","📡 Surveillance Technology","🏭 Vendor-Specific Research","🌐 Roaming \u0026 Interconnect Security","⚖️ Legal Notice","Recent Updates (2024-2025)","Vendor-Specific Research","Getting Started","Attack Vectors","Cellular IoT and NB-IoT Security","International Research","Roaming and Interconnect Security","Testing and Research Methodologies","Conference Talks","Research Papers","Detection and Defense","Private 5G Network Security","Automotive and Industrial Cellular","Vulnerability Disclosure","SIM Security","Recent CVEs and Updates"],"sub_categories":["SDR Hardware Options","Latest Base Station Software \u0026 Tools","Security Alerts \u0026 Advisories","Additional Conference Resources","Conferences to Follow","Stingray/IMSI Catchers","Notable Researchers and Organizations to Follow","GSM/CDMA Traffic Impersonation and Interception","Base Station Software","Configuration Guides","Black Hat 2022","Black Hat 2021","Research Equipment Used in \"Over The Air Baseband Exploit\"","IMSI Catcher Detection \u0026 Research","5G Security Research","LTE/4G Security Research","Radio Jamming Attacks","SS7 Attack Research","Legal \u0026 Regulatory","Conferences and Competitions","Base Station Software and Tools (Updated)","Analysis Tools","Development \u0026 Analysis Tools","New Research (2025-2026)","Lab Environments","Research Collections","2024 Research","DefCon 32 (2024)","Vulnerability Research Tools","Black Hat 2024","TROOPERS 2013","NDSS 2025","🚨 Protection from Stingrays \u0026 IMSI Catchers","New Research (2025)","Mailing Lists and Forums","Stingray / IMSI Catchers","Key Concepts to Understand First","Security Advisories","Development and Analysis Tools","IRC and Chat","GitHub Collections","New Research (2024)","Additional Reading","Modern Baseband Fuzzing (2024-2026)","Overshadowing Attacks (2024-2026)","Black Hat Asia 2026","Black Hat USA 2025","DEF CON 33 (August 2025)","DEF CON 32 (August 2024)","OffensiveCon 2025","USENIX Security 2023","2026","2025","2024","2019-2022","Protection from Stingrays and IMSI Catchers","SIM Swap Attack Prevention and Detection","2026 Notable CVEs","2024-2025 Notable CVEs","CVE Resources","Professional Training","Video Tutorials"],"readme":"# Awesome Cellular Hacking\n\n\u003e A comprehensive curated list of resources for 2G/3G/4G/5G cellular security research and analysis\n\nThis repository consolidates community knowledge in the cellular security space, including exploits, research papers, tools, and educational resources. The goal is to preserve and organize important security research that might otherwise become difficult to find.\n\n**Disclaimer:** This information is intended for educational and defensive security research purposes only. Use responsibly and in compliance with applicable laws and regulations.\n\n## Table of Contents\n\n- [Getting Started](#getting-started)\n- [Rogue Base Stations](#rogue-base-stations)\n- [Recent Updates (2024-2026)](#recent-updates-2024-2026)\n- [Software and Tools](#software-and-tools)\n- [Hardware Setup](#hardware-setup)\n- [Testing and Research Methodologies](#testing-and-research-methodologies)\n- [Attack Vectors](#attack-vectors)\n- [Conference Talks](#conference-talks)\n- [Research Papers](#research-papers)\n- [Equipment and Hardware](#equipment-and-hardware)\n- [Detection and Defense](#detection-and-defense)\n- [Cellular IoT and NB-IoT Security](#cellular-iot-and-nb-iot-security)\n- [Satellite-Cellular Integration](#satellite-cellular-integration)\n- [Private 5G Network Security](#private-5g-network-security)\n- [Network Slicing and Edge Security](#network-slicing-and-edge-security)\n- [Automotive and Industrial Cellular](#automotive-and-industrial-cellular)\n- [Forensics and Investigation](#forensics-and-investigation)\n- [Vulnerability Disclosure](#vulnerability-disclosure)\n- [SIM Security](#sim-security)\n- [SS7 and Telecom Infrastructure](#ss7-and-telecom-infrastructure)\n- [Surveillance Technology](#surveillance-technology)\n- [Recent CVEs and Updates](#recent-cves-and-updates)\n- [International Research](#international-research)\n- [Training and Education](#training-and-education)\n- [Vendor-Specific Research](#vendor-specific-research)\n- [Roaming and Interconnect Security](#roaming-and-interconnect-security)\n- [Community](#community)\n- [Resources](#resources)\n\n---\n\n## Getting Started\n\nNew to cellular security research? This section outlines the recommended path for building foundational skills.\n\n### Skill Levels\n\n**Beginner (passive listening only)**\n- Hardware: RTL-SDR V3 or V4 ($35-$40), a laptop running Linux\n- Software: GNU Radio, GQRX, gr-gsm\n- First project: Scan and decode GSM frames passively using gr-gsm and Wireshark\n- Reading: [NIST SP 800-187 LTE Security Guide](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-187.pdf)\n\n**Intermediate (active research lab)**\n- Hardware: HackRF One or LimeSDR Mini ($139-$350), programmable SIM cards (sysmoUSIM), a spare Android device\n- Software: srsRAN 4G, Open5GS or Free5GC, OsmocomBB\n- First project: Build a private LTE network in a Faraday cage and connect a test device\n- Reading: srsRAN documentation, Open5GS tutorials\n\n**Advanced (protocol fuzzing and baseband research)**\n- Hardware: USRP B210 or BladeRF 2.0, multiple test devices\n- Software: 5GBaseChecker, LTEFuzz, BaseBridge, SigPloit, FirmWire, 5GHOUL\n- Focus areas: Baseband fuzzing, RAN-Core interface testing, SS7/Diameter signaling\n\n### Lab Setup Checklist\n\n- [ ] Linux host (Ubuntu 22.04 or 24.04 recommended)\n- [ ] UHD drivers installed and device recognized (`uhd_find_devices`)\n- [ ] Faraday cage or RF shielding for active transmissions\n- [ ] Programmable SIM cards (sysmoUSIM-SJA2 or similar)\n- [ ] Dedicated test devices (not your daily driver)\n- [ ] Isolated network environment (no production network access)\n\n### Key Concepts to Understand First\n\n- [3GPP Architecture Overview](https://www.3gpp.org/technologies/keywords-acronyms/98-lte): how UE, eNodeB, MME, SGW, PGW fit together\n- [IMSI, IMEI, TMSI](https://en.wikipedia.org/wiki/International_mobile_subscriber_identity): subscriber identity fundamentals\n- [AKA Protocol](https://www.3gpp.org/ftp/specs/archive/33_series/33.401/): how authentication works in LTE\n\n---\n\n## Rogue Base Stations\n\n### GSM/CDMA Traffic Impersonation and Interception\n\n- **[How To Build Your Own Rogue GSM BTS For Fun and Profit](https://www.evilsocket.net/2016/03/31/How-To-Build-Your-Own-Rogue-GSM-BTS-For-Fun-And-Profit/)**\n\n  Guide to creating a portable GSM BTS for private networks or security testing. Covers technical setup using relatively inexpensive hardware.\n\n- **[How to Create an Evil LTE Twin / LTE Rogue BTS](https://adam-toscher.medium.com/how-to-create-an-evil-lte-twin-34b0a9ce193b)**\n\n  Tutorial for setting up a 4G/LTE Evil Twin base station using srsRAN and USRP SDR devices.\n\n- **[Practical Attacks Against GSM Networks: Impersonation](https://blog.blazeinfosec.com/practical-attacks-against-gsm-networks-part-1/)**\n\n  Detailed analysis of GSM base station impersonation using SDR and open source tools.\n\n- **[Tutorial: Analyzing GSM with Airprobe and Wireshark](https://www.rtl-sdr.com/rtl-sdr-tutorial-analyzing-gsm-with-airprobe-and-wireshark/)**\n\n  Step-by-step guide for using RTL-SDR to analyze GSM signals with GR-GSM/Airprobe and Wireshark.\n\n- **[GSM/GPRS Traffic Interception for Penetration Testing](https://research.nccgroup.com/2016/05/19/gsm-gprs-traffic-interception-for-penetration-testing-engagements/)**\n\n  NCC Group research on GSM/GPRS interception capabilities for penetration testing engagements.\n\n---\n\n## Recent Updates (2024-2026)\n\n### New Research (2025-2026)\n\n- **[SNI5GECT: Sniffing and Injecting 5G Traffic Without Rogue Base Stations](https://thehackernews.com/2025/08/new-sni5gect-attack-crashes-phones-and.html)** — Singapore University of Technology and Design, USENIX Security 2025\n\n  Framework that enables sniffing unencrypted 5G messages and injecting attack payloads over-the-air without jamming or rogue base stations. An attacker within 20 meters can force devices to reboot and downgrade to 4G. [GitHub](https://github.com/asset-group/5ghoul-5g-nr-attacks)\n\n- **[5Gone: Uplink Overshadowing Attacks in 5G-SA](https://arxiv.org/abs/2602.10272)** — ETH Zurich, Feb 2026\n\n  SDR-based uplink overshadowing attack against 5G-SA networks exploiting 3GPP standard deficiencies. Enables surgical DoS, privacy, and downgrade attacks with E2E latency under 500μs. Runs on standard x86 hardware without dedicated acceleration.\n\n- **[Kairos: Timing-Induced Interaction Failures in LTE and 5G Core Networks](https://arxiv.org/abs/2605.30985)** — 2026\n\n  Lightweight testing framework exposing timing-induced interaction failures. Discovered 20 new vulnerabilities and reproduced 34 existing issues across Open5GS, srsRAN, Amarisoft, and commercial implementations.\n\n- **[RANsacked: 100+ Flaws in LTE and 5G Implementations](https://thehackernews.com/2025/01/ransacked-over-100-security-flaws-found.html)** — University of Florida / NC State, Jan 2025\n\n  Researchers disclosed 119 vulnerabilities (97 CVEs) across seven LTE and three 5G implementations including Open5GS, Magma, OpenAirInterface, Athonet, SD-Core, srsRAN. Every flaw can be used to persistently disrupt city-wide cellular communications. Some require no SIM card — a single unauthenticated packet can crash an MME or AMF.\n\n- **[CITesting: Context Integrity Violations in LTE Core Networks](https://dl.acm.org/doi/10.1145/3719027.3765230)** — KAIST, ACM CCS 2025 (Distinguished Paper)\n\n  KAIST researchers identified a new class of uplink attacks against LTE core networks. Unlike traditional downlink attacks, these work through legitimate base stations and can affect anyone in the same MME coverage area. All four tested implementations (Open5GS, srsRAN, Amarisoft, Nokia) were vulnerable.\n\n- **[LLFuzz: LLM-Guided Baseband Firmware Fuzzing](https://arxiv.org/abs/2507.09660)** — KAIST, July 2025\n\n  LLM-guided fuzzing framework for cellular baseband firmware targeting MediaTek and Samsung Shannon. Discovered 11 memory corruption vulnerabilities including buffer overflows in NAS and RRC message handlers. Leverages LLM to generate semantically valid protocol messages.\n\n- **[Uncovering Hidden Paths in 5G: Protocol Tunneling and Network Boundary Bridging](https://dl.acm.org/doi/10.1145/3719027.3765206)** — ACM CCS 2025\n\n  New research on exploiting protocol tunneling in 5G networks to cross network boundaries and reach components that should be isolated.\n\n- **[BaseBridge: Over-the-Air and Emulation Testing for Cellular Baseband Firmware](https://github.com/FirmWire/BaseBridge)** — IEEE S\u0026P 2025\n\n  Bridges the gap between over-the-air and emulation-based testing for cellular baseband firmware analysis. Extends the FirmWire emulator.\n\n- **[From Control to Chaos: Formal Analysis of 5G Access Control](https://sp2025.ieee-security.org/accepted-papers.html)** — Penn State, IEEE S\u0026P 2025\n\n  Comprehensive formal analysis of 5G's access control mechanisms, uncovering critical vulnerabilities.\n\n- **[Devilray: Adversarial Model Revealing Blind Spots in Fake Base Station Detection](https://arxiv.org/abs/2605.19232)** — May 2026\n\n  Systematic adversarial baseline exploring realistic FBS evasion strategies. Evaluates 7 detectors and identifies gaps in coverage across 2,592 feasible FBS configurations.\n\n- **[GLaDoS: Location-aware Denial-of-Service of Cellular Networks](https://dl.acm.org/doi/10.5555/3766078.3766351)** — USENIX Security 2025\n\n  Location-aware DoS attacks targeting specific geographical areas in cellular networks.\n\n- **[Breaking 5G on The Lower Layer](https://arxiv.org/abs/2602.10250)** — 2026\n\n  Lower-layer exploitation research presenting SIB1 spoofing and Timing Advance manipulation attacks during random access procedures.\n\n- **[5G Network Slicing: Security Challenges, Attack Vectors, and Mitigation](https://pmc.ncbi.nlm.nih.gov/articles/PMC12251764/)** — PMC, July 2025\n\n  Comprehensive classification of attacks across orchestration, virtualization, and inter-slice communication layers in 5G.\n\n- **[Survey on 5G Physical Layer Security Threats and Countermeasures](https://www.mdpi.com/1424-8220/24/17/5523)** — MDPI Sensors, 2024\n\n  In-depth review of PHY layer attack surface in 4G/5G: jamming, spoofing, eavesdropping, pilot contamination, and current SDR-based research tooling.\n\n### New Research (2024)\n\n- **[Hermes: Unlocking Security Analysis of Cellular Network Protocols](https://www.usenix.org/conference/usenixsecurity24/presentation/al-ishtiaq)** — USENIX Security 2024\n\n  End-to-end framework to automatically generate formal FSM representations from natural language cellular specifications. Achieves 81-87% accuracy and uncovers 3 new vulnerabilities plus 19 previous attacks in 4G/5G specifications. [GitHub](https://github.com/SyNSec-den/hermes-spec-to-fsm)\n\n- **[CellularLint: Identifying Inconsistent Behavior in Cellular Network Specifications](https://www.usenix.org/conference/usenixsecurity24/presentation/rahman)** — USENIX Security 2024\n\n  Semi-automatic framework for inconsistency detection in 4G/5G standards using few-shot learning on domain-adapted LLMs. [GitHub](https://github.com/CellularLint/cellularlint-codes)\n\n- **[Logic Gone Astray: Security Analysis of 5G Basebands](https://www.usenix.org/conference/usenixsecurity24/)** — USENIX Security 2024\n\n  Control plane protocol security analysis framework for 5G baseband implementations.\n\n- **[ASTRA-5G: Automated Over-the-Air Security Testing](https://dl.acm.org/doi/abs/10.1145/3643833.3656141)** — WiSec 2024\n\n  Open-source framework automating security testing for 5G SA devices by leveraging enhanced core and RAN software. [Research Paper](https://research.google/pubs/astra-5g-automated-over-the-air-security-testing-and-research-architecture-for-5g-sa-devices/)\n\n- **[5GBaseChecker Tool Release](https://github.com/SyNSec-den/5GBaseChecker)** — Penn State University, Black Hat 2024\n\n  Open-source tool for detecting vulnerabilities in 5G baseband implementations. Used to find 12 critical bugs in Samsung, MediaTek, and Qualcomm chipsets affecting Google, OPPO, OnePlus, Motorola, and Samsung devices.\n\n### Base Station Software and Tools (Updated)\n\n- **[OpenBTS 2024 Reloaded](https://github.com/PentHertz/OpenBTS)** — Updated for modern UHD drivers and Ubuntu 22.04/24.04\n- **[OpenAirInterface (OAI)](https://openairinterface.org/)** — Complete 3GPP Release-15+ implementation with active 5G development\n- **[LimeNET CrowdCell](https://limemicro.com/)** — Network-in-a-box with integrated LimeSDR for small cell deployments\n- **[Amarisoft LTEENB/gNB](https://www.amarisoft.com/)** — Professional-grade LTE/5G NR base station software\n- **[DragonOS](https://sourceforge.net/projects/dragonos-focal/)** — Debian/Lubuntu-based SDR distro with cellular tools pre-installed; supports RTL-SDR, HackRF, LimeSDR, BladeRF; latest release is DragonOS Noble (24.04). [Website](https://cemaxecuter.com/)\n- **[WarDragon](https://cemaxecuter.com/)** — Passive RF sensor platform with AI-enhanced cellular survey capabilities; integrates with TAK; includes Ransack for multi-RAT survey\n- **[Magma Core Network](https://magmacore.org/)** — Meta's distributed packet core, now under the Linux Foundation\n- **[5GBaseChecker](https://github.com/SyNSec-den/5GBaseChecker)** — Automated 5G baseband vulnerability detection tool\n- **[Ransack](https://github.com/alphafox02/ransack)** — Multi-RAT cellular survey/recon platform; unifies LTE/5G NR/GSM/NB-IoT observations from SDRs, Qualcomm phones, and Rayhunter into SQLite with REST API\n- **[5GHOUL](https://github.com/asset-group/5ghoul-5g-nr-attacks)** — 5G NR fuzzing and attack framework targeting Qualcomm/MediaTek\n\n---\n\n## Software and Tools\n\n### Base Station Software\n\n| Software | Description | Link |\n|----------|-------------|------|\n| **OpenBTS (2024 Reloaded)** | Updated Linux SDR-based GSM air interface for modern systems | [GitHub](https://github.com/PentHertz/OpenBTS) |\n| **OpenBTS (Original)** | Range Networks implementation | [SourceForge](https://sourceforge.net/projects/openbts/) |\n| **YateBTS** | GSM/GPRS radio access network implementation | [Website](https://yatebts.com/) |\n| **srsRAN Project** | Open-source 5G O-RAN CU/DU software suite | [GitHub](https://github.com/srsran/srsRAN_Project) |\n| **srsRAN 4G** | Open-source 4G software radio suite | [GitHub](https://github.com/srsran/srsRAN_4G) |\n| **OpenAirInterface** | Complete 4G/5G protocol stack | [Website](https://openairinterface.org/) |\n| **Free5GC** | Open-source 5G core network implementation | [GitHub](https://github.com/free5gc/free5gc) |\n| **Open5GS** | Open-source 5G core and EPC implementation | [GitHub](https://github.com/open5gs/open5gs) |\n| **Kamailio** | Open-source SIP server used in IMS/VoLTE labs | [Website](https://www.kamailio.org/) |\n\n### Configuration Guides\n\n- **[BladeRF and YateBTS Configuration](https://github.com/Nuand/bladeRF/wiki/Setting-up-Yate-and-YateBTS-with-the-bladeRF)**\n- **[srsRAN Project Documentation](https://docs.srsran.com/projects/project)**\n- **[srsRAN 4G Documentation](https://docs.srsran.com/projects/4g)**\n\n### Analysis Tools\n\n| Tool | Description | Link |\n|------|-------------|------|\n| **Ransack** | Multi-RAT cellular survey platform for DragonOS; merges LTE/5G NR/GSM/NB-IoT into unified DB; orchestrates srsRAN, LTESniffer, FALCON, Rayhunter | [GitHub](https://github.com/alphafox02/ransack) |\n| **Rayhunter** | EFF's IMSI catcher detector for Orbic hotspots; detects 2G downgrades and suspicious requests | [GitHub](https://github.com/EFForg/rayhunter) |\n| **5GBaseChecker** | Automated 5G baseband vulnerability detection (Penn State) | [GitHub](https://github.com/SyNSec-den/5GBaseChecker) |\n| **5GHOUL** | 5G NR attacks against Qualcomm/MediaTek with stateful fuzzer | [GitHub](https://github.com/asset-group/5ghoul-5g-nr-attacks) |\n| **FirmWire** | Full-system baseband firmware emulation for fuzzing/debugging | [GitHub](https://github.com/FirmWire/FirmWire) |\n| **BaseBridge** | Bridges OTA and emulation testing for baseband firmware | [GitHub](https://github.com/FirmWire/BaseBridge) |\n| **LTE-Cell-Scanner** | LTE cell detection and analysis | [GitHub](https://github.com/Evrytania/LTE-Cell-Scanner) |\n| **gr-gsm** | GSM analysis with GNU Radio | [GitHub](https://github.com/ptrkrysik/gr-gsm/wiki/Passive-IMSI-Catcher) |\n| **IMSI-Catcher Detector** | Android app for detecting IMSI catchers | [GitHub](https://github.com/CellularPrivacy/Android-IMSI-Catcher-Detector) |\n| **CellGuard** | iOS app detecting rogue base stations via baseband analysis | [GitHub](https://github.com/seemoo-lab/CellGuard) |\n| **QCSuper** | Capture 2G-4G traffic using Qualcomm phones | [P1 Security](https://labs.p1sec.com/2019/07/09/presenting-qcsuper-a-tool-for-capturing-your-2g-3g-4g-air-traffic-on-qualcomm-based-phones/) |\n| **FALCON LTE** | Fast analysis of LTE control channels in real-time | [GitHub](https://github.com/falkenber9/falcon) |\n| **Kalibrate** | GSM base station scanner and frequency calibration | [GitHub](https://github.com/scateu/kalibrate-hackrf) |\n| **LTE Sniffer** | Open-source LTE downlink/uplink eavesdropper | [GitHub](https://github.com/SysSec-KAIST/LTESniffer) |\n| **OsmocomBB** | Free firmware for mobile phone baseband processors | [Osmocom](https://osmocom.org/projects/osmocombb) |\n| **Modmobmap** | Mobile network mapping | [GitHub](https://github.com/Synacktiv-contrib/Modmobmap) |\n| **Modmobjam** | Mobile jamming research tool | [GitHub](https://github.com/Synacktiv-contrib/Modmobjam) |\n| **CITesting** | Context integrity violation testing for LTE core networks | [ACM DL](https://dl.acm.org/doi/10.1145/3719027.3765230) |\n| **SigPloit** | SS7/Diameter/GTP/SIP signaling security testing framework | [GitHub](https://github.com/SigPloiter/SigPloit) |\n| **LTEFuzz** | LTE protocol fuzzer (KAIST) | [GitHub](https://github.com/koo7/LTEFuzz) |\n| **LLFuzz** | LLM-guided baseband firmware fuzzing for MediaTek/Samsung Shannon | [Paper](https://arxiv.org/abs/2507.09660) |\n| **Crocodile Hunter** | EFF tool for detecting rogue cell towers by wardriving | [GitHub](https://github.com/EFForg/crocodile-hunter) |\n| **SCAT** | Signaling Collection and Analysis Tool for Qualcomm/Samsung | [GitHub](https://github.com/fgsect/scat) |\n| **Hermes** | FSM synthesis from natural language specifications | [GitHub](https://github.com/SyNSec-den/hermes-spec-to-fsm) |\n| **CellularLint** | Inconsistency detection in 4G/5G standards | [GitHub](https://github.com/CellularLint/cellularlint-codes) |\n| **5GReasoner** | Property-directed formal verification of 5G control-plane protocols | [Paper](https://dl.acm.org/doi/10.1145/3319535.3354263) |\n| **DoLTEst** | Downlink negative testing framework for LTE devices; 1,848 test cases | [Paper](https://www.usenix.org/conference/usenixsecurity22/presentation/park-cheoljun) |\n| **ProChecker** | FSM extraction + model checking for 4G LTE implementations | [Paper](https://www.researchgate.net/publication/353412860) |\n| **LTEInspector** | Property-driven adversarial model-based testing for 4G LTE | [Paper](https://syed-rafiul-hussain.github.io/index.php/teaching/cse543-f21/docs/lteinspector.pdf) |\n| **BASECOMP** | Comparative analysis for baseband integrity protection | [GitHub](https://github.com/kaist-hacking/BaseComp) |\n| **BaseTrace** | Framework for iPhone baseband interface research | [GitHub](https://github.com/seemoo-lab/BaseTrace) |\n| **ss7map** | SS7 network exposure mapping | [P1 Security](https://ss7map.p1sec.com/) |\n| **Osmocom Suite** | Complete open-source GSM/GPRS stack | [Osmocom](https://osmocom.org/projects) |\n\n---\n\n## Hardware Setup\n\n### USRP Installation on Linux\n\n```bash\n# Add Ettus Research repository\nsudo add-apt-repository ppa:ettusresearch/uhd\nsudo apt-get update\n\n# Install UHD drivers and tools\nsudo apt-get install libuhd-dev libuhd003 uhd-host\n\n# Find connected devices\nuhd_find_devices\n\n# Download firmware images\ncd /usr/lib/uhd/utils/\n./uhd_images_downloader.py\n\n# Test device connection\nsudo uhd_usrp_probe\n```\n\n### SDR Hardware Options\n\n| Hardware | Frequency Range | Bandwidth | Price Range | Use Case | Link |\n|----------|----------------|-----------|-------------|----------|------|\n| **Ettus Research (USRP)** | | | | | |\n| **USRP B210** | 70 MHz - 6 GHz | 61.44 MHz | $2,100 | Professional development, 2x2 MIMO | [Ettus](https://www.ettus.com/all-products/ub210-kit/) |\n| **USRP B200mini** | 70 MHz - 6 GHz | 61.44 MHz | $775 | Compact USRP B-series | [Ettus](https://www.ettus.com/) |\n| **USRP N210** | DC - 6 GHz | 25 MHz | $1,700 | High-performance networked SDR | [Ettus](https://www.ettus.com/) |\n| **USRP N320** | 1 MHz - 6 GHz | 200 MHz | $8,000 | Networked 2x2 MIMO | [Ettus](https://www.ettus.com/) |\n| **USRP X310** | DC - 6 GHz | 160 MHz | $6,000 | High-performance desktop/rack | [Ettus](https://www.ettus.com/all-products/x310-kit/) |\n| **USRP X410** | 1 MHz - 7.2 GHz | 400 MHz | $15,000 | Latest high-performance 4x4 MIMO | [Ettus](https://www.ettus.com/) |\n| **USRP X440** | 30 MHz - 4 GHz | 1.6 GHz | $25,000+ | Latest 8x8 MIMO RFSoC platform | [Ettus](https://www.ettus.com/) |\n| **USRP E320** | 70 MHz - 6 GHz | 56 MHz | $4,000 | Embedded 2x2 MIMO SDR | [Ettus](https://www.ettus.com/) |\n| **Nuand (BladeRF)** | | | | | |\n| **BladeRF 2.0 xA4** | 47 MHz - 6 GHz | 61.44 MHz | $420 | Budget 2x2 MIMO development | [Nuand](https://www.nuand.com/product/bladerf-xa4/) |\n| **BladeRF 2.0 xA9** | 47 MHz - 6 GHz | 61.44 MHz | $720 | High FPGA resources, 2x2 MIMO | [Nuand](https://www.nuand.com/product/bladerf-xa9/) |\n| **BladeRF x40 (Legacy)** | 300 MHz - 3.8 GHz | 40 MHz | $400 | Entry-level legacy model | [Nuand](https://www.nuand.com/product/bladerf-x40/) |\n| **Great Scott Gadgets** | | | | | |\n| **HackRF One** | 1 MHz - 6 GHz | 20 MHz | $350 | Budget TX/RX development | [GSG](https://greatscottgadgets.com/hackrf/) |\n| **YARD Stick One** | 300-348, 391-464, 782-928 MHz | 2.5 MHz | $110 | Sub-GHz IoT frequencies | [GSG](https://greatscottgadgets.com/yardstickone/) |\n| **Lime Microsystems** | | | | | |\n| **LimeSDR USB** | 100 kHz - 3.8 GHz | 61.44 MHz | $289 | Open-source 2x2 MIMO | [Lime Micro](https://limemicro.com/sdr/limesdr-usb/) |\n| **LimeSDR Mini** | 10 MHz - 3.5 GHz | 30.72 MHz | $139 | Compact LimeSDR variant | [Lime Micro](https://limemicro.com/boards/limesdr-mini/) |\n| **LimeSDR Mini 2.0** | 10 MHz - 3.5 GHz | 30.72 MHz | $169 | Updated with ECP5 FPGA | [Lime Micro](https://limemicro.com/sdr/limesdr-mini-2-0/) |\n| **LimeSDR X3** | Various bands | Up to 61.44 MHz | $3,000+ | Professional 3x transceiver PCIe | [Lime Micro](https://limemicro.com/sdr/limesdr-x3/) |\n| **Analog Devices** | | | | | |\n| **PlutoSDR** | 325 MHz - 3.8 GHz | 20 MHz | $150 | Education and learning platform | [Analog Devices](https://www.analog.com/en/design-center/evaluation-hardware-and-software/evaluation-boards-kits/adalm-pluto.html) |\n| **RTL-SDR Blog** | | | | | |\n| **RTL-SDR V3** | 500 kHz - 1.75 GHz | 3.2 MHz | $35 | Ultra-budget RX-only scanner | [RTL-SDR](https://www.rtl-sdr.com/buy-rtl-sdr-dvb-t-dongles/) |\n| **RTL-SDR V4** | 500 kHz - 1.75 GHz | 3.2 MHz | $40 | Latest with R828D tuner | [RTL-SDR](https://www.rtl-sdr.com/rtl-sdr-blog-v4-dongle-initial-release/) |\n| **Airspy** | | | | | |\n| **Airspy R2** | 24 MHz - 1.8 GHz | 10 MHz | $200 | High-performance VHF/UHF scanner | [Airspy](https://airspy.com/) |\n| **Airspy Mini** | 24 MHz - 1.8 GHz | 6 MHz | $99 | Compact Airspy in dongle format | [Airspy](https://airspy.com/) |\n| **Airspy HF+ Discovery** | 9 kHz - 31 MHz, 60-260 MHz | 768 kHz | $169 | Dedicated HF reception | [Airspy](https://airspy.com/) |\n| **SDRplay** | | | | | |\n| **RSP1A** | 1 kHz - 2 GHz | 10 MHz | $119 | Wideband general purpose | [SDRplay](https://www.sdrplay.com/) |\n| **RSPdx** | 1 kHz - 2 GHz | 10 MHz | $299 | Professional features, dual antenna | [SDRplay](https://www.sdrplay.com/) |\n| **Red Pitaya** | | | | | |\n| **STEMlab 125-14** | DC - 60 MHz | 50 MHz | $600 | HF transceiver, lab instrument | [Red Pitaya](https://redpitaya.com/) |\n| **STEMlab 122-16** | DC - 50 MHz | Variable | $625 | High-resolution HF SDR/scope | [Red Pitaya](https://redpitaya.com/) |\n\n### Common SDR Issues and Troubleshooting\n\n| Issue | Possible Causes |\n|-------|----------------|\n| Device not detected | Improper firmware, USB connection issues |\n| Poor signal quality | Incorrect antennas, wrong frequency configuration |\n| Connection failures | Wrong SIM, incorrect MCC/MNC codes |\n| Performance issues | Virtualized platform limitations, wrong SDR firmware |\n\n---\n\n## Testing and Research Methodologies\n\n### Modern Baseband Fuzzing (2024-2026)\n\n- **[SNI5GECT: Practical 5G Traffic Injection](https://thehackernews.com/2025/08/new-sni5gect-attack-crashes-phones-and.html)** — USENIX Security 2025\n\n  Sniff and inject 5G messages without rogue base stations or jamming. Demonstrated 4G downgrade attacks within 20 meters of victim. [GitHub](https://github.com/asset-group/5ghoul-5g-nr-attacks)\n\n- **[\"NASty\" 5G Baseband Vulnerabilities through Dependency-Aware Fuzzing](https://www.youtube.com/watch?v=gXGIo5fy800)** — Black Hat USA 2025\n\n  Targeting Non-Access Stratum (NAS) layer vulnerabilities using dependency-aware fuzzing. Discovered security bypass using \"!!FAKE-TESTHARNESS!!\" message. Symbolic execution challenges with Samsung Shannon basebands requiring TB-level memory.\n\n- **[Budget-Friendly Baseband Fuzzing Setup](https://t2.fi/schedule/2024/)** — DefCon 32, Janne Taponen\n\n  Covers building cost-effective baseband fuzzing rigs using SDRs, using LLMs to accelerate protocol parser development, and testing automotive ECUs, payment terminals, and mobile devices.\n\n- **[RANsacked Fuzzing Framework](https://dl.acm.org/doi/10.1145/3658644.3670320)** — University of Florida / NC State, ACM CCS 2024\n\n  Domain-informed fuzzing approach targeting RAN-Core interfaces. Discovered 119 vulnerabilities across ten network implementations.\n\n- **[BaseBridge](https://github.com/FirmWire/BaseBridge)** — IEEE S\u0026P 2025\n\n  Framework that bridges over-the-air and emulation-based testing for cellular baseband firmware. Extends FirmWire.\n\n- **[FirmWire](https://github.com/FirmWire/FirmWire)** — NDSS 2022\n\n  Full-system baseband firmware emulation platform for Samsung and MediaTek. Discovered 8 remote memory corruptions including 3 pre-authentication RCE vulnerabilities.\n\n### Vulnerability Research Tools\n\n- **[5GBaseChecker](https://github.com/SyNSec-den/5GBaseChecker)** — Automated 5G baseband vulnerability detection\n- **[5GHOUL](https://github.com/asset-group/5ghoul-5g-nr-attacks)** — Stateful 5G NR fuzzer with OTA attack capabilities\n- **[LLFuzz](https://arxiv.org/abs/2507.09660)** — LLM-guided baseband fuzzing for MediaTek/Samsung Shannon (KAIST 2025)\n- **[CITesting](https://dl.acm.org/doi/10.1145/3719027.3765230)** — Context integrity violation testing for LTE core networks\n- **[Kairos](https://arxiv.org/abs/2605.30985)** — Timing-induced interaction failure testing\n- **[ASTRA-5G](https://research.google/pubs/astra-5g-automated-over-the-air-security-testing-and-research-architecture-for-5g-sa-devices/)** — Automated OTA security testing for 5G SA devices\n- **[certmitm](https://github.com/juurlink/certmitm)** — TLS implementation testing tool\n\n---\n\n## Attack Vectors\n\n### Radio Jamming Attacks\n\nFrom [NIST SP 800-187](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-187.pdf):\n\n- **Smart Jamming** — Targeted channel interference timed to avoid detection\n- **Dumb Jamming** — Broadband noise across frequency ranges\n- **UE Interface Jamming** — Preventing UE signaling to eNodeB\n- **eNodeB Interface Jamming** — Disrupting base station communications\n\n### Overshadowing Attacks (2024-2026)\n\n- **[5Gone: Uplink Overshadowing in 5G-SA](https://arxiv.org/abs/2602.10272)** — Feb 2026\n\n  Uplink overshadowing attack transmitting at same time/frequency as victim with higher power. Enables surgical DoS, privacy leaks, and downgrade attacks. Runs on COTS x86 hardware.\n\n- **[AdaptOver: Adaptive Overshadowing Attacks](https://arxiv.org/abs/2106.05039)** — 2022\n\n  Adversary can decode, overshadow, and inject arbitrary messages OTA in either direction. Can cause persistent DoS (≥12h) or force IMSI transmission in plaintext. Demonstrated on live LTE/5G-NSA networks at 3.8km range.\n\n### 5G Security Research\n\n- **[SNI5GECT: Sniffing and Injecting 5G Traffic](https://arxiv.org/abs/2505.00000)** — USENIX Security 2025\n- **[Breaking 5G on The Lower Layer](https://arxiv.org/abs/2602.10250)** — SIB1 spoofing and TA manipulation attacks\n- **[Privacy Attacks on 4G/5G Paging Protocols](https://assets.documentcloud.org/documents/5749002/4G-5G-paper-at-NDSS-2019.pdf)** — NDSS 2019\n- **[European 5G Security in the Wild](https://arxiv.org/pdf/2305.08635.pdf)** — 2023\n- **[5G Threat Modeling Framework](https://arxiv.org/pdf/2005.05110v1.pdf)**\n- **[ENISA 5G Threat Landscape](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/5g/ENISA-5G-threat-landscape.pdf)**\n- **[5GReasoner Analysis Framework](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/5g/5GReasoner.pdf)**\n- **[5G NR Jamming, Spoofing, and Sniffing](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/5g/5gjam.pdf)**\n- **[New Privacy Threat on 3G, 4G, and 5G AKA Protocols](https://arxiv.org/pdf/1905.07617.pdf)**\n- **[Insecure Connection Bootstrapping in Cellular Networks](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/lte/wisec19-preprint.pdf)**\n- **[Protecting 4G and 5G Cellular Paging Protocols](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/5g/popets-2020-0008.pdf)**\n- **[Uncovering Hidden Paths in 5G: Protocol Tunneling](https://dl.acm.org/doi/10.1145/3719027.3765206)** — ACM CCS 2025\n- **[5G Network Slicing Attack Classification](https://pmc.ncbi.nlm.nih.gov/articles/PMC12251764/)** — MDPI, July 2025\n\n### LTE/4G Security Research\n\n- **[LTRACK: Stealthy Mobile Phone Tracking](https://www.usenix.org/system/files/sec22summer_kotuliak.pdf)** — USENIX Security 2022\n- **[Detecting Fake 4G Base Stations in Real Time](https://i.blackhat.com/USA-20/Wednesday/us-20-Quintin-Detecting-Fake-4G-Base-Stations-In-Real-Time.pdf)** — Black Hat 2020\n- **[BaseSAFE: Baseband Fuzzing](https://arxiv.org/pdf/2005.07797.pdf)**\n- **[LTE Public Warning System Attacks](https://netstech.org/wp-content/uploads/2019/06/cmas-mobisys2019.pdf)**\n- **[Signal Overshadowing Attacks](https://www.usenix.org/system/files/sec19-yang-hojoon.pdf)** — USENIX Security 2019\n- **[Breaking LTE on Layer Two](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/lte/breaking-lte-layer-two.pdf)**\n- **[LTE/LTE-A Jamming, Spoofing, and Sniffing](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/lte/LTE-jamming-magazine.pdf)**\n- **[LTE Protocol Exploits](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/lte/LTE-security-TakeDownCon.pdf)**\n- **[Practical Attacks Against Privacy and Availability](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/lte/Prac-4G-Attacks.pdf)**\n- **[LTE Security Assessment](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/lte/LTE-open-source-HackerHalted.pdf)**\n- **[LTE Security Disabled: Misconfiguration in Commercial Networks](https://www.infsec.ruhr-uni-bochum.de/media/infsec/veroeffentlichungen/2019/04/23/wisec19-final123.pdf)**\n- **[All The 4G Modules Could Be Hacked](https://i.blackhat.com/USA-19/Wednesday/us-19-Shupeng-All-The-4G-Modules-Could-Be-Hacked.pdf)** — Black Hat 2019\n- **[Paging Storm Attacks Against 4G/LTE Networks](https://www.cs.binghamton.edu/~ghyan/papers/wisec20.pdf)**\n- **[Analysis of the LTE Control Plane](https://syssec.kaist.ac.kr/pub/2019/kim_sp_2019.pdf)** — IEEE S\u0026P 2019\n- **[Baseband Attacks: Remote Exploitation of Memory Corruptions](https://www.usenix.org/system/files/conference/woot12/woot12-final24.pdf)** — WOOT 2012\n- **[Full Chain Baseband Exploits](https://labs.taszk.io/articles/post/full_chain_bb_part1/)** — taszk.io; zero-click RCE in baseband and Android runtime\n- **[Unburdened By What Has Been: Exploiting L2 for Baseband RCE on Samsung Exynos](https://labs.taszk.io/articles/post/there_will_be_bugs/)** — taszk.io; CVE-2023-41111, CVE-2023-41112\n- **[CITesting: Context Integrity Violations in LTE Core Networks](https://dl.acm.org/doi/10.1145/3719027.3765230)** — ACM CCS 2025 (Distinguished Paper)\n- **[New Vulnerabilities in 4G and 5G Cellular Access Network Protocols](https://dl.acm.org/doi/10.1145/3317549.3319728)** — WiSec 2019\n\n---\n\n## Conference Talks\n\n### Black Hat Asia 2026\n\n- **[Qualcomm BootROM Vulnerability (CVE-2026-25262)](https://www.kaspersky.com/blog/qualcomm-cve-2026-25262/55811/)** — Kaspersky ICS CERT\n\n  Hardware-level vulnerability in Qualcomm chipsets' Emergency Download Mode (EDL). Unpatchable BootROM flaw allows attackers with physical access to write arbitrary data to memory, potentially gaining full device control. Affects MDM9x07, MDM9x45, MDM9x65, MSM8909, MSM8916, MSM8952, SDX50 series.\n\n### Black Hat USA 2025\n\n- **[Uncovering 'NASty' 5G Baseband Vulnerabilities through Dependency-Aware Fuzzing](https://www.youtube.com/watch?v=gXGIo5fy800)**\n\n  Non-Access Stratum (NAS) layer vulnerability research using dependency-aware fuzzing. Revealed security bypass via \"!!FAKE-TESTHARNESS!!\" message and challenges with Samsung Shannon baseband symbolic execution. [Slides](https://github.com/sixteen250/BlackHat_USA2025_Sessions)\n\n- **[Uncovering Threats and Exposing Vulnerabilities in Next-Gen Cellular RAN](https://www.youtube.com/watch?v=rqzK1xd3wng)**\n\n  Research on 5G Radio Access Networks transitioning to disaggregated, software-driven O-RAN architectures.\n\n### DEF CON 33 (August 2025)\n\n- **[Gateways to Chaos: How We Proved Modems Are a Ticking Time Bomb](https://www.youtube.com/watch?v=kItqWJHN_dI)** — Chiao-Lin \"Steven Meow\" Yu, Trend Micro\n\n  Over 35 severe flaws in ISP-supplied modems (ADSL, fiber, cable, 4G/5G) rooted in outdated IoT SDKs. Affects power grids, water systems, ATMs globally.\n\n- **[Hacking Hotspots: Pre-Auth RCE and Arbitrary SMS on 4G/5G Routers](https://infocondb.org/con/def-con/def-con-33/hacking-hotspots-pre-auth-remote-code-execution-arbitrary-sms-adjacent-attacks-on-5g-and-4glte-routers)**\n\n  Reverse-engineering firmware of Tuoshi and KuWFi 4G/5G routers revealing pre-auth RCE and arbitrary SMS injection.\n\n### Black Hat USA 2024\n\n- **[5G Baseband Vulnerabilities — Penn State University](https://techcrunch.com/2024/08/07/hackers-could-spy-on-cellphone-users-by-abusing-5g-baseband-flaws-researchers-say/)**\n\n  Researchers disclosed 12 vulnerabilities in 5G basebands from Samsung, MediaTek, and Qualcomm, affecting devices from Google, OPPO, OnePlus, Motorola, and Samsung. Released 5GBaseChecker tool.\n\n### DEF CON 32 (August 2024)\n\n- **[Economizing Mobile Network Warfare: Budget-Friendly Baseband Fuzzing](https://t2.fi/schedule/2024/)** — Janne Taponen\n\n  Making baseband fuzzing accessible with affordable SDR hardware. Covers LLM-assisted protocol parser development and vulnerability discovery across automotive ECUs, payment terminals, and cellular modems.\n\n- **[RF Attacks on Aviation's Defense Against Mid-Air Collisions](https://www.rtl-sdr.com/sdr-and-rf-videos-from-defcon-32/)**\n- **[Breaking the Beam: Exploiting VSAT Modems from Earth](https://www.rtl-sdr.com/sdr-and-rf-videos-from-defcon-32/)**\n- **[GPS Spoofing: It's About Time, Not Just Position](https://www.rtl-sdr.com/sdr-and-rf-videos-from-defcon-32/)**\n\n### OffensiveCon 2025\n\n- **[No Signal, No Security: Dynamic Baseband Vulnerability Research](https://securityboulevard.com/2025/06/offensivecon25-no-signal-no-security-dynamic-baseband-vulnerability-research/)** — Daniel Klischies, David Hirsch\n\n  Dynamic approaches to baseband vulnerability research.\n\n- **[Mobile Network Attacks: Exploiting Smartphones Through Baseband](https://www.offensivecon.org/trainings/2025/exploiting-smartphones-through-baseband.html)** — Training\n\n  Hands-on training covering cellular network fundamentals (2G-5G), baseband OS internals, and vulnerability exploitation techniques.\n\n### ACM CCS 2025\n\n- **[CITesting: Systematic Testing of Context Integrity Violations in LTE Core Networks](https://dl.acm.org/doi/10.1145/3719027.3765230)** — KAIST (Distinguished Paper)\n\n  New class of uplink attacks against LTE core networks that work through legitimate base stations — no rogue BTS required. All four tested implementations were vulnerable, including commercial systems from Nokia and Amarisoft.\n\n- **[Uncovering Hidden Paths in 5G: Exploiting Protocol Tunneling and Network Boundary Bridging](https://dl.acm.org/doi/10.1145/3719027.3765206)**\n\n  Demonstrates how attackers can use protocol tunneling to traverse network boundaries and reach isolated 5G components.\n\n### IEEE S\u0026P 2025\n\n- **[BaseBridge: Bridging Over-the-Air and Emulation Testing for Cellular Baseband Firmware](https://github.com/FirmWire/BaseBridge)**\n\n  Framework for cellular baseband firmware security testing combining emulation and OTA approaches.\n\n- **[From Control to Chaos: A Comprehensive Formal Analysis of 5G's Access Control](https://sp2025.ieee-security.org/accepted-papers.html)** — Penn State\n\n### USENIX Security 2025\n\n- **[SNI5GECT: A Practical Approach to Inject aNRchy into 5G NR](https://thehackernews.com/2025/08/new-sni5gect-attack-crashes-phones-and.html)** — Singapore University of Technology and Design\n\n- **[GLaDoS: Location-aware Denial-of-Service of Cellular Networks](https://dl.acm.org/doi/10.5555/3766078.3766351)**\n\n### USENIX Security 2024\n\n- **[Hermes: Unlocking Security Analysis of Cellular Network Protocols](https://www.usenix.org/conference/usenixsecurity24/presentation/al-ishtiaq)**\n\n  Automatic FSM generation from natural language specifications. Uncovered 3 new vulnerabilities and identified 19 previous attacks.\n\n- **[CellularLint: Identifying Inconsistent Behavior in Cellular Network Specifications](https://www.usenix.org/conference/usenixsecurity24/presentation/rahman)**\n\n  LLM-based inconsistency detection in 4G/5G standards.\n\n- **[Logic Gone Astray: Security Analysis of 5G Basebands](https://www.usenix.org/conference/usenixsecurity24/)**\n\n  Control plane protocol analysis framework.\n\n### USENIX Security 2023\n\n- **[BASECOMP: A Comparative Analysis for Integrity Protection in Cellular Baseband Software](https://www.usenix.org/conference/usenixsecurity23/presentation/kim-eunsoo)**\n\n  Semi-automated integrity protection analysis using probabilistic inference. Discovered 29 bugs including critical NAS AKA bypass in Samsung. [GitHub](https://github.com/kaist-hacking/BaseComp)\n\n### Previous Years\n\n- **[Black Hat USA 2022: Attacks from a New Front Door in 4G and 5G Networks](https://i.blackhat.com/USA-22/Wednesday/US-22-Shaik-Attacks-From-a-New-Front-Door-in-4G-5G-Mobile-Networks.pdf)**\n- **[Black Hat USA 2021: Over The Air Baseband Exploit — 5G RCE](https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Over-The-Air-Baseband-Exploit-Gaining-Remote-Code-Execution-On-5G-Smartphones.pdf)** — [White Paper](https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Over-The-Air-Baseband-Exploit-Gaining-Remote-Code-Execution-On-5G-Smartphones-wp.pdf)\n- **[Black Hat USA 2020: Detecting Fake 4G Base Stations in Real Time](https://i.blackhat.com/USA-20/Wednesday/us-20-Quintin-Detecting-Fake-4G-Base-Stations-In-Real-Time.pdf)**\n- **[NSA PLAYSET GSM](https://www.defcon.org/images/defcon-22/dc-22-presentations/Pierce-Loki/DEFCON-22-Pierce-Loki-NSA-PLAYSET-GSM.pdf)** — DEF CON 22\n- **[VoLTE Phreaking](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/talks/HAXPO-VoLTE-Phreaking-Ralph-Moonen.pdf)** — Ralph Moonen\n- **[RF Exploitation: IoT/OT Hacking with SDR](https://conference.hitb.org/hitbsecconf2019ams/materials/HAXPO%20D2%20-%20Demystifying%20IoT:OT%20Hacks%20With%20SDR%20-%20Himanshu%20Mehta%20\u0026%20Harshit%20Agrawal.pdf)** — HITB 2019\n- **[Bye-Bye IMSI Catchers: Security Enhancements in 5G](https://conference.hitb.org/hitbsecconf2018pek/materials/D2T2%20-%20Bye%20Bye%20IMSI%20Catchers%20-%20Security%20Enhancements%20in%205g%20-%20Lin%20Huang.pdf)** — HITB 2018\n- **[Side Channel Attacks in 4G and 5G](https://i.blackhat.com/eu-19/Thursday/eu-19-Hussain-Side-Channel-Attacks-In-4G-And-5G-Cellular-Networks.pdf)** — Black Hat Europe 2019\n- **[Dirty Use of USSD Codes in Cellular Networks](https://troopers.de/wp-content/uploads/2012/12/TROOPERS13-Dirty_use_of_USSD_codes_in_cellular-Ravi_Borgaonkor.pdf)** — TROOPERS 2013, Ravi Borgaonkar\n- **[Hacking LTE Public Warning Systems](https://conference.hitb.org/hitbsecconf2019ams/materials/HAXPO%20D1%20-%20Hacking%20LTE%20Public%20Warning%20Systems%20-%20Weiguang%20Li.pdf)** — HITB 2019\n\n---\n\n## Research Papers\n\n### 2026\n\n- **[5Gone: Uplink Overshadowing Attacks in 5G-SA](https://arxiv.org/abs/2602.10272)** — ETH Zurich, Feb 2026\n\n  SDR-based uplink overshadowing exploiting 3GPP standard deficiencies. E2E latency under 500μs on COTS hardware.\n\n- **[Breaking 5G on The Lower Layer](https://arxiv.org/abs/2602.10250)** — 2026\n\n  SIB1 spoofing and Timing Advance manipulation attacks during random access.\n\n- **[Kairos: Timing-Induced Interaction Failures in LTE and 5G Core Networks](https://arxiv.org/abs/2605.30985)** — 2026\n\n  Discovered 20 new vulnerabilities and reproduced 34 issues across open-source and commercial cores.\n\n- **[Devilray: Adversarial Model Revealing Blind Spots in Fake Base Station Detection](https://arxiv.org/abs/2605.19232)** — May 2026\n\n  Systematic adversarial baseline evaluating 7 FBS detectors across 2,592 configurations.\n\n- **[Security Overview and Analysis of 3GPP 5G MAC CE](https://arxiv.org/abs/2506.09502)** — June 2026\n\n  Analysis of 5G NR Medium Access Control protocol specification (3GPP V18.5.0).\n\n- **[Semantics Over Syntax: Uncovering Pre-Authentication 5G Baseband Vulnerabilities](https://arxiv.org/abs/2604.04283)** — April 2026\n\n  Automated approach to finding pre-auth vulnerabilities in 5G basebands using semantic analysis.\n\n### 2025\n\n- **[CITesting: Systematic Testing of Context Integrity Violations in LTE Core Networks](https://dl.acm.org/doi/10.1145/3719027.3765230)** — ACM CCS 2025 (Distinguished Paper Award)\n\n  KAIST's CITesting tool runs thousands of test cases against LTE core implementations, dwarfing the 31-case coverage of prior tooling (LTEFuzz). All four tested implementations contained CIV vulnerabilities.\n\n- **[Uncovering Hidden Paths in 5G: Protocol Tunneling and Network Boundary Bridging](https://dl.acm.org/doi/10.1145/3719027.3765206)** — ACM CCS 2025\n\n- **[5G Network Slicing: Security Challenges, Attack Vectors, and Mitigation Approaches](https://pmc.ncbi.nlm.nih.gov/articles/PMC12251764/)** — MDPI, July 2025\n\n- **[Starshields for iOS: Navigating the Security Cosmos in Satellite Communication](https://www.ndss-symposium.org/wp-content/uploads/2025-124-paper.pdf)** — NDSS 2025\n\n  First comprehensive security analysis of Apple's satellite communication features. Researchers reverse-engineered the proprietary protocol, demonstrated restriction bypasses, and built a simulation testbed covering Emergency SOS, Find My, roadside assistance, and iMessage over satellite.\n\n- **[RANsacked: A Domain-Informed Approach for Fuzzing LTE and 5G RAN-Core Interfaces](https://thehackernews.com/2025/01/ransacked-over-100-security-flaws-found.html)** — University of Florida / NC State, Jan 2025\n\n  119 vulnerabilities, 97 CVEs, across ten implementations. Any one enables city-wide disruption.\n\n- **[SNI5GECT: A Practical Approach to Inject aNRchy into 5G NR](https://www.kaspersky.com/blog/5g-attack-downgrade-sni5gect/54258/)** — USENIX Security 2025\n\n- **[GLaDoS: Location-aware Denial-of-Service of Cellular Networks](https://dl.acm.org/doi/10.5555/3766078.3766351)** — USENIX Security 2025\n\n- **[LLFuzz: LLM-Guided Baseband Firmware Fuzzing](https://arxiv.org/abs/2507.09660)** — KAIST, July 2025\n\n  LLM-guided fuzzing framework targeting MediaTek and Samsung Shannon basebands. Discovered 11 memory corruption vulnerabilities in NAS/RRC message handlers. Uses LLM to generate semantically valid protocol messages for improved coverage.\n\n- **[BaseBridge: Bridging Over-the-Air and Emulation Testing for Cellular Baseband Firmware](https://github.com/FirmWire/BaseBridge)** — IEEE S\u0026P 2025\n\n- **[From Control to Chaos: Formal Analysis of 5G Access Control](https://sp2025.ieee-security.org/accepted-papers.html)** — IEEE S\u0026P 2025\n\n### 2024\n\n- **[Hermes: Unlocking Security Analysis of Cellular Network Protocols](https://www.usenix.org/conference/usenixsecurity24/presentation/al-ishtiaq)** — USENIX Security 2024\n\n  Automatic FSM synthesis from natural language. 81-87% accuracy, 3 new vulnerabilities, 19 previous attacks identified.\n\n- **[CellularLint: Identifying Inconsistent Behavior in Cellular Specifications](https://www.usenix.org/conference/usenixsecurity24/presentation/rahman)** — USENIX Security 2024\n\n- **[Logic Gone Astray: Security Analysis of 5G Basebands](https://www.usenix.org/conference/usenixsecurity24/)** — USENIX Security 2024\n\n- **[ASTRA-5G: Automated Over-the-Air Security Testing for 5G SA Devices](https://dl.acm.org/doi/abs/10.1145/3643833.3656141)** — WiSec 2024\n\n- **[Catch You Cause I Can: Busting Rogue Base Stations using CellGuard](https://dl.acm.org/doi/10.1145/3678890.3678898)** — RAID 2024\n\n- **[Survey on 5G Physical Layer Security Threats and Countermeasures](https://www.mdpi.com/1424-8220/24/17/5523)** — MDPI Sensors 2024\n\n  Comprehensive review of PHY-layer attack surface covering eavesdropping, jamming, spoofing, pilot contamination, and SDR-based research frameworks.\n\n- **[The Impact of IMSI Catcher Deployments on Cellular Network Security](https://arxiv.org/abs/2405.00793)** — 2024\n\n### 2023\n\n- **[BASECOMP: A Comparative Analysis for Integrity Protection in Cellular Baseband Software](https://www.usenix.org/conference/usenixsecurity23/presentation/kim-eunsoo)** — USENIX Security 2023\n\n  Semi-automated integrity protection analysis. Discovered 29 bugs including critical NAS AKA bypass in Samsung.\n\n- **[European 5G Security in the Wild](https://arxiv.org/pdf/2305.08635.pdf)** — 2023\n\n### 2019-2022\n\n- **[FirmWire: Transparent Dynamic Analysis for Cellular Baseband Firmware](https://cise.ufl.edu/~butler/pubs/ndss22-firmwire.pdf)** — NDSS 2022\n- **[Privacy Attacks on 4G/5G Paging Protocols](https://assets.documentcloud.org/documents/5749002/4G-5G-paper-at-NDSS-2019.pdf)** — NDSS 2019\n- **[New Vulnerabilities in 4G and 5G Cellular Access Network Protocols](https://dl.acm.org/doi/10.1145/3317549.3319728)** — WiSec 2019\n\n  Three new attack classes exploiting unprotected device capability information: identification, bidding-down, and battery drain.\n\n- **[New Privacy Threat on 3G, 4G, and Upcoming 5G AKA Protocols](https://arxiv.org/pdf/1905.07617.pdf)**\n- **[BaseSAFE: Baseband SAnitized Fuzzing through Emulation](https://arxiv.org/pdf/2005.07797.pdf)**\n- **[AdaptOver: Adaptive Overshadowing Attacks in Cellular Networks](https://arxiv.org/abs/2106.05039)** — 2022\n\n  OTA message injection at 3.8km range. Demonstrated on live LTE/5G-NSA networks.\n\n---\n\n## Equipment and Hardware\n\n### Research Equipment Used in \"Over The Air Baseband Exploit\"\n\n| Component | Purpose | Link |\n|-----------|---------|------|\n| Ettus USRP B210 | Software Defined Radio | [Product Page](https://www.ettus.com/all-products/ub210-kit/) |\n| srsENB | 4G/5G Base Station Software | [GitHub](https://github.com/srsran/srsRAN/tree/master/srsenb) |\n| Open5GS | 5G Core Network | [GitHub](https://github.com/open5gs) |\n| sysmo-usim-tool | SIM Programming | [Project Page](https://osmocom.org/projects/cellular-infrastructure/wiki/SysmoISIM-SJA2) |\n| pysim | SIM Analysis Tool | [GitHub](https://github.com/osmocom/pysim) |\n| CoIMS | VoLTE Testing | [Play Store](https://play.google.com/store/apps/details?id=com.sherle.coims) |\n| Docker Open5GS | Containerized Core | [Tutorial](https://open5gs.org/open5gs/docs/tutorial/03-VoLTE-dockerized/) |\n\n---\n\n## Detection and Defense\n\n### Protection from Stingrays and IMSI Catchers\n\n- **[Rayhunter](https://github.com/EFForg/rayhunter)** — EFF, 2025\n\n  Open-source IMSI catcher detector that runs on affordable Orbic mobile hotspots (~$20-30). Analyzes control traffic in real-time looking for 2G downgrade attempts and unusual IMSI requests. Thousands deployed worldwide with community-contributed packet captures. [Documentation](https://efforg.github.io/rayhunter/) — [Blog Post](https://www.eff.org/deeplinks/2025/03/meet-rayhunter-new-open-source-tool-eff-detect-cellular-spying)\n\n- **[CellGuard](https://github.com/seemoo-lab/CellGuard)** — SEEMOO Lab, 2024\n\n  iOS app that detects rogue base stations by analyzing baseband packets in real-time. Integrates with the Apple Cell Location Database for anomaly detection. [Website](https://cellguard.seemoo.tu-darmstadt.de/) — [Research Paper](https://dl.acm.org/doi/10.1145/3678890.3678898)\n\n- **[BaseTrace](https://github.com/seemoo-lab/BaseTrace)** — SEEMOO Lab\n\n  Framework for researching the interface between iPhone's application processor and baseband.\n\n### IMSI Catcher Detection and Research\n\n- **[SeaGlass: City-Wide IMSI-Catcher Detection](https://seaglass.cs.washington.edu/)** — UW\n- **[SeaGlass Research Paper](https://seaglass-web.s3.amazonaws.com/SeaGlass___PETS_2017.pdf)** — PETS 2017\n- **[Evaluating IMSI Catcher Detectors](http://www.cs.ox.ac.uk/files/9192/paper-final-woot-imsi.pdf)** — Oxford\n- **[IMSI-Catcher Detector (Android)](https://github.com/CellularPrivacy/Android-IMSI-Catcher-Detector)**\n- **[Devilray: Adversarial FBS Detection Analysis](https://arxiv.org/abs/2605.19232)** — May 2026\n\n### Security Advisories\n\n- **[CERT Alert: VoLTE Implementation Vulnerabilities](https://www.kb.cert.org/vuls/id/943167/)**\n\n---\n\n## Cellular IoT and NB-IoT Security\n\n- **[NB-IoT Security Analysis Framework](https://arxiv.org/search/?query=NB-IoT+security)** — Narrowband IoT security research\n- **[Cat-M1/LTE-M Attack Vectors](https://www.gsma.com/iot/mobile-iot-security/)** — GSMA IoT security guidelines\n- **[Monitoring 5G Core Networks Vulnerabilities With eBPF](https://ieeexplore.ieee.org/document/10870553)** — IEEE Networking Letters 2025\n\n---\n\n## Satellite-Cellular Integration\n\n- **[Starshields for iOS: Satellite Communication Security](https://www.ndss-symposium.org/wp-content/uploads/2025-124-paper.pdf)** — NDSS 2025\n- **[3GPP Non-Terrestrial Networks (NTN) Security](https://www.3gpp.org/specifications/specification-numbering)** — Official 5G satellite integration specs\n- **[LEO Satellite Cellular Vulnerabilities](https://arxiv.org/search/?query=satellite+cellular+security)** — Low Earth Orbit security research\n\n---\n\n## Private 5G Network Security\n\n- **[O-RAN Alliance Security Update 2025](https://www.o-ran.org/blog/o-ran-alliance-security-update-2025)** — WG11 security assurance program and AI/ML threat analysis\n- **[O-RAN Security Risks and Vulnerabilities](https://www.sciencedirect.com/science/article/pii/S1389128626004925)** — 60% of risks are DoS/performance degradation; xApp compromise threats\n- **[Open RAN: Attack of the xApps](https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/open-ran-attack-of-the-xapps)** — Trend Micro analysis of Near-RT RIC vulnerabilities\n- **[End-to-End O-RAN Security Architecture](https://arxiv.org/abs/2304.05513)** — Threat surface analysis including Open Fronthaul\n- **[Private 5G Penetration Testing Guide](https://www.nist.gov/cybersecurity)** — Enterprise private network testing\n- **[Campus 5G Security Assessment](https://csrc.nist.gov/)** — NIST private 5G security guidance\n- **[Security Implications of 5G Communication in Industrial Systems](https://arxiv.org/abs/2604.11509)** — 2024\n\n---\n\n## Network Slicing and Edge Security\n\n- **[5G Network Slicing Attack Research](https://pmc.ncbi.nlm.nih.gov/articles/PMC12251764/)** — MDPI, July 2025\n- **[Multi-Access Edge Computing (MEC) Vulnerabilities](https://www.etsi.org/technologies/multi-access-edge-computing)** — ETSI MEC security specs\n- **[Network Function Virtualization (NFV) Attacks](https://www.etsi.org/technologies/nfv)** — Virtual network function security\n\n---\n\n## Automotive and Industrial Cellular\n\n- **[Security Analysis of LTE Connectivity in Connected Cars: Tesla Case Study](https://arxiv.org/abs/2510.22024)** — 2025\n- **[V2X Security Research](https://www.its.dot.gov/research_areas/emerging_tech/htm/EmerTech_V2X.htm)** — Vehicle-to-everything communications\n- **[Cellular-V2X Attack Vectors](https://ieeexplore.ieee.org/search/searchresult.jsp?queryText=C-V2X+security)** — Automotive cellular security\n- **[BMW Security Assessment using OpenBTS](https://keenlab.tencent.com/en/whitepapers/Experimental_Security_Assessment_of_BMW_Cars_by_KeenLab.pdf)** — Keen Lab / Tencent\n\n---\n\n## Forensics and Investigation\n\n- **[XRY Mobile Forensics](https://msab.com/products/xry/)** — Commercial cellular forensics platform\n- **[Cellebrite UFED](https://cellebrite.com/)** — Mobile device extraction tools\n- **[NIST Mobile Forensics Guidelines](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-101r1.pdf)** — NIST SP 800-101r1\n\n---\n\n## Vulnerability Disclosure\n\n- **[Android Security Bulletins](https://source.android.com/docs/security/bulletin)** — Regular Android/baseband patches\n- **[Qualcomm Security Bulletins](https://www.qualcomm.com/company/product-security/bulletins)** — Snapdragon security updates\n- **[Samsung Mobile Security](https://security.samsungmobile.com/)** — Galaxy security research program\n- **[Samsung Semiconductor Security Updates](https://semiconductor.samsung.com/support/quality-support/product-security-updates/)** — Shannon baseband CVEs\n- **[Apple Security Research](https://security.apple.com/)** — iOS/baseband security program\n\n---\n\n## SIM Security\n\n### SIM Swap Attack Prevention and Detection\n\n- **[iVerify SIM Swap Detection](https://www.iverify.io/)** — Mobile security platform with SIM swap attack detection capabilities\n- **[ML-Based SIM Swap Detection Research](https://arxiv.org/search/?query=SIM+swap+detection)** — Machine learning approaches to detecting SIM swap fraud patterns\n- **[T-Mobile SIM Protection](https://www.t-mobile.com/support/account/account-security)** — Carrier SIM protection features (Account Takeover Protection)\n- **[CTIA SIM Swap Best Practices](https://www.ctia.org/)** — Industry guidelines for SIM swap fraud prevention\n\n### SIM Vulnerability Research\n\n- **[Rooting SIM Cards](https://media.blackhat.com/us-13/us-13-Nohl-Rooting-SIM-cards-Slides.pdf)** — Black Hat 2013, Karsten Nohl\n- **[SIM Port Hack Case Study](https://medium.com/coinmonks/the-most-expensive-lesson-of-my-life-details-of-sim-port-hack-35de11517124)**\n- **[Cloning 3G/4G SIM Cards With a PC and an Oscilloscope](https://www.blackhat.com/docs/us-15/materials/us-15-Yu-Cloning-3G-4G-SIM-Cards-With-A-PC-And-An-Oscilloscope-Lessons-Learned-In-Physical-Security-wp.pdf)** — Black Hat 2015\n\n---\n\n## SS7 and Telecom Infrastructure\n\n### SS7 Attack Research\n\n- **[Bypassing GSMA SS7 Recommendations](https://github.com/W00t3k/Awesome-Cellular-Hacking/blob/master/papers/ss7/Bypassing-GSMA-SS7-Kirill-Puzankov.pdf)** — Kirill Puzankov\n- **[Attacking SS7 Networks](http://www.hackitoergosum.org/2010/HES2010-planglois-Attacking-SS7.pdf)** — HES 2010\n- **[SS7: Locate. Track. Manipulate.](https://media.ccc.de/v/31c3_-_6249_-_en_-_saal_1_-_201412271715_-_ss7_locate_track_manipulate_-_tobias_engel)** — 31C3 2014, Tobias Engel; live demonstration of cross-network subscriber tracking\n- **[SS7 Map](https://ss7map.p1sec.com/)** — P1 Security; map of SS7 exposure across global carriers\n- **[Diameter Vulnerabilities Exposure](https://www.gsma.com/security/resources/fs-07-diameter-security/)** — GSMA FS.07; official Diameter security guidance for 4G roaming\n- **[GSMA FS.11 SS7 Security](https://www.gsma.com/security/resources/fs-11-ss7-security/)** — GSMA baseline SS7 network security requirements\n\n### SS7/Diameter Testing Tools\n\n- **[SigPloit](https://github.com/SigPloiter/SigPloit)** — Modular testing framework for SS7, Diameter, GTP, and SIP; covers location tracking, call/SMS interception, and DoS scenarios\n- **[ss7map](https://ss7map.p1sec.com/)** — Automated SS7 network topology and exposure mapper\n- **[SCTP scanner](https://github.com/adagilabs/sctp_scanner)** — Discovers SCTP-based SS7 endpoints on IP networks\n\n---\n\n## Surveillance Technology\n\n### Stingray / IMSI Catchers\n\n- **[DHS Stingray Surveillance](https://www.wired.com/story/dcs-stingray-dhs-surveillance/)** — Wired\n- **[Stingray Cost Analysis](https://www.vice.com/en_us/article/gv5k3x/heres-how-much-a-stingray-cell-phone-surveillance-tool-costs)** — Vice\n- **[NYCLU Stingray Information](https://www.nyclu.org/en/stingrays)**\n- **[EFF: Cell Site Simulators / IMSI Catchers](https://www.eff.org/pages/cell-site-simulatorsimsi-catchers)**\n- **[WiFi IMSI Catcher](https://www.blackhat.com/docs/eu-16/materials/eu-16-OHanlon-WiFi-IMSI-Catcher.pdf)** — Black Hat Europe 2016\n\n---\n\n## Recent CVEs and Updates\n\n### 2026 Notable CVEs\n\n- **[CVE-2026-25262](https://www.kaspersky.com/blog/qualcomm-cve-2026-25262/55811/)** — Qualcomm BootROM (Sahara protocol) unpatchable vulnerability; affects MDM9x07, MDM9x45, MDM9x65, MSM8909, MSM8916, MSM8952, SDX50 series\n- **[CVE-2026-21385](https://socprime.com/blog/cve-2026-21386-vulnerability/)** — Qualcomm Graphics memory corruption; exploited in targeted attacks on Android\n- **[MediaTek March 2026 Bulletin](https://corp.mediatek.com/product-security-bulletin/March-2026)** — CVE-2026-20423 through CVE-2026-20445 affecting MT7902, MT7920, MT7921, MT7922, MT7925, MT7927\n\n### 2024-2025 Notable CVEs\n\n- **[CVE-2023-24033 (Google Project Zero)](https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote.html)** — Samsung Exynos baseband: internet-to-baseband RCE via malformed SDP in VoLTE/VoWiFi; no user interaction required. Part of 18 zero-day disclosure affecting Pixel 6/7, Galaxy S22, Vivo, and Samsung wearables\n- **[CVE-2024-55568](https://nvd.nist.gov/vuln/detail/CVE-2024-55568)** — Samsung Exynos baseband heap buffer overflow in SDP parsing; remote code execution via crafted VoLTE packets\n- **[CVE-2024-25073](https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-25073/)** — Samsung Shannon baseband: pointer not properly checked in Call Control module, leads to DoS\n- **[CVE-2025-58349](https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-58349/)** — Samsung: incorrect handling of LTE MAC packets with many MAC Control Elements causes baseband crash\n- **[Open5GS CVEs (2024-2025)](https://www.cvedetails.com/vulnerability-list/vendor_id-22759/year-2025/Open5gs.html)** — Multiple DoS vulnerabilities including NULL pointer dereferences and assertion failures\n- **[RANsacked: 97 CVEs](https://thehackernews.com/2025/01/ransacked-over-100-security-flaws-found.html)** — Affecting Open5GS, Magma, OAI, Athonet, SD-Core, NextEPC, srsRAN\n\n### CVE Resources\n\n- **[NVD CVE Search](https://nvd.nist.gov/vuln/search)** — Search for cellular-related CVEs\n- **[Google Project Zero](https://googleprojectzero.blogspot.com/)** — Ongoing mobile security research\n- **[Samsung Security Bulletins](https://security.samsungmobile.com/securityUpdate.smc)** — Regular baseband updates\n- **[SIMjacker Research](https://simjacker.com/)** — SIM-based attack evolution\n- **[Free5GC CVEs](https://app.opencve.io/cve/?vendor=free5gc)** — OpenCVE tracking\n\n---\n\n## International Research\n\n- **[ENISA 5G Reports](https://www.enisa.europa.eu/)** — EU 5G security assessments\n- **[KAIST SysSec Lab](https://syssec.kaist.ac.kr/)** — Leading cellular security research group (CITesting, LTEFuzz, LTESniffer, BASECOMP)\n- **[Penn State SyNSec Lab](https://syed-rafiul-hussain.github.io/)** — Syed Rafiul Hussain's group (5GBaseChecker, Hermes, CellularLint)\n- **[Japanese 5G Security Guidelines](https://www.nisc.go.jp/eng/)** — Japan national cybersecurity strategy\n- **[ASSET Research Group (Singapore)](https://asset-group.github.io/)** — 5GHOUL, SNI5GECT research\n\n---\n\n## Training and Education\n\n### Professional Training\n\n- **[OffensiveCon: Mobile Network Attacks Training](https://www.offensivecon.org/trainings/2025/exploiting-smartphones-through-baseband.html)** — Hands-on baseband exploitation (2G-5G)\n- **[SANS Mobile Security](https://www.sans.org/)** — Professional mobile security courses\n- **[Offensive Security Mobile Testing](https://www.offensive-security.com/)** — Advanced mobile penetration testing\n- **[PentHertz Training](https://penthertz.com/)** — RF and wireless security training\n\n### Lab Environments\n\n- **[Open5GS + srsRAN Lab Setup](https://github.com/s5uishida/open5gs_5gc_srsran_sample_config)** — Complete 5G SA config with ZeroMQ UE/RAN\n- **[End-to-End Open5GS-srsRAN Guide](https://github.com/ngkore/Open5GS-srsRAN)** — Deployment guide for Ubuntu 22.04\n- **[5G SA Lab Setup Tutorial](https://himanshup.hashnode.dev/5g-sa-lab-setup-using-srsran-open5gs)** — Step-by-step srsRAN + Open5GS guide\n- **[OpenAirInterface Lab Setup](https://github.com/OpenAirInterface/openairinterface5g)** — Open-source 5G lab environment\n- **[DragonOS](https://sourceforge.net/projects/dragonos-focal/)** — Pre-configured SDR Linux distribution; latest is Noble (24.04)\n- **[5G Security Datasets](https://github.com/DLTeamTUC/5GDatasets)** — PCAP, CSV, and AMF logs for flooding/fuzzing/replay attacks on Open5GS, OAI, Amarisoft\n- **[GNU Radio / SDR University Courses](https://www.gnuradio.org/)** — SDR educational materials\n- **[VET5G: Virtual Testbed for 5G Security](https://arxiv.org/abs/2507.20873)** — OpenAirInterface + Android emulator testbed\n\n---\n\n## Vendor-Specific Research\n\n- **[Ericsson Security Research](https://www.ericsson.com/en/security)**\n- **[Nokia Bell Labs Security](https://www.bell-labs.com/)**\n- **[Qualcomm Security Bulletins](https://www.qualcomm.com/company/product-security/bulletins)**\n- **[MediaTek Product Security](https://www.mediatek.com/)**\n- **[Samsung Shannon Baseband Research](https://semiconductor.samsung.com/support/quality-support/product-security-updates/)**\n- **[Google Project Zero: 18 Exynos Zero-Days (2023)](https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote.html)** — CVE-2023-24033 and 17 others; 4 RCE without user interaction via VoLTE/VoWiFi\n- **[Google Project Zero: Exynos Baseband CVE-2024-55568](https://googleprojectzero.blogspot.com/)** — Heap buffer overflow in Samsung Exynos baseband allowing remote code execution\n\n---\n\n## Roaming and Interconnect Security\n\n- **[GRX/IPX Security Research](https://www.gsma.com/newsroom/)** — GSMA roaming security\n- **[Diameter Protocol Security](https://tools.ietf.org/html/rfc6733)** — 4G/5G signaling security\n- **[GSMA FS.19 IPX Security](https://www.gsma.com/security/resources/fs-19-ipe-security/)** — Security requirements for IPX providers handling roaming traffic\n- **[Roaming Attacks via Diameter](https://www.p1sec.com/blog/diameter-roaming-attacks/)** — P1 Security analysis of Diameter-based roaming attack surface\n- **[GTP Vulnerabilities in 4G/5G Roaming](https://www.a1qa.com/blog/gtp-vulnerabilities-mobile-network-security/)** — GTP-C and GTP-U attack surface at the roaming interface\n- **[AdaptiveMobile SS7 Firewall Research](https://www.adaptivemobile.com/resources)** — Carrier-grade SS7/Diameter firewall bypass techniques\n\n---\n\n## Resources\n\n### GitHub Collections\n\n- **[Cellular-Security-Papers](https://github.com/onehouwong/Cellular-Security-Papers)** — Comprehensive collection of academic papers, tools, and talks\n- **[Awesome-Cellular-Hacking](https://github.com/W00t3k/Awesome-Cellular-Hacking)** — This repository\n- **[Firmware-Analysis-Papers](https://github.com/onehouwong/Firmware-Analysis-Papers)** — Baseband and firmware security papers\n- **[5GSEC](https://github.com/5GSEC)** — 5G security research organization\n\n### Development and Analysis Tools\n\n- **[RTL-SDR Community](https://www.rtl-sdr.com/)** — SDR resources and tutorials\n- **[MCC-MNC Database](http://www.mcc-mnc.com/)** — Mobile Country/Network Code reference\n- **[RFSec-ToolKit](https://github.com/cn0xroot/RFSec-ToolKit)** — RF security testing tools\n- **[cellularsecurity.org](https://cellularsecurity.org/)** — Community resource for cellular security research\n\n### Research Collections\n\n- **[RF Security Documentation](https://rmusser.net/docs/Wireless.html#cn)**\n- **[USENIX Security Papers](https://www.usenix.org/conferences)** — Security conference proceedings\n- **[ACM Digital Library](https://dl.acm.org/)** — ACM research papers\n- **[IEEE Xplore](https://ieeexplore.ieee.org/)** — IEEE research database\n\n### Legal and Regulatory\n\n- **[FCC Equipment Authorization Rules](https://www.fcc.gov/general/equipment-authorization-procedures)** — US cellular equipment regulations\n- **[CISA 5G Security Guidance](https://www.cisa.gov/)** — US critical infrastructure guidance\n- **[NIST 5G Cybersecurity](https://www.nist.gov/cybersecurity)** — NIST cellular security frameworks\n\n### Video Tutorials\n\n- **[DragonOS FocalX Cellular Security Research w/ LTESniffer (Part 1)](https://www.youtube.com/watch?v=5AVPC0KcbMY)** — srsRAN, LimeSDR, B205mini setup\n- **[DragonOS FocalX Cellular Security Research + IMSI Capture w/ LTESniffer (Part 3)](https://www.youtube.com/watch?v=Lu4Vt_RE0MA)** — X310, srsRAN advanced config\n- **[RTL-SDR SDR and RF Videos from DEF CON 32](https://www.rtl-sdr.com/sdr-and-rf-videos-from-defcon-32/)** — Collection of RF/cellular talks\n\n### Additional Reading\n\n- **[Analyzing GSM Downlink with USRP](http://leetupload.com/blagosphere/2014/03/28/analyze-and-crack-gsm-downlink-with-a-usrp/)**\n- **[AT\u0026T Microcell Analysis](https://fail0verflow.com/blog/2012/microcell-fail/)**\n- **[LTE Recon — DefCon 23](https://www.rtl-sdr.com/one-more-rtl-sdr-talk-from-defcon-23/)**\n- **[LTE Security Guide — NIST SP 800-187](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-187.pdf)**\n- **[LTE Pwnage: Core Network Elements](https://conference.hitb.org/hitbsecconf2013ams/materials/D1T2%20-%20Philippe%20Langlois%20-%20Hacking%20HLR%20HSS%20and%20MME%20Core%20Network%20Elements.pdf)** — HITB 2013\n\n---\n\n## Community\n\n### Mailing Lists and Forums\n\n- **[Osmocom Mailing Lists](https://lists.osmocom.org/mailman/listinfo)** — Active developer and user lists for OpenBTS, OsmocomBB, srsRAN topics\n- **[srsRAN Discussions](https://github.com/srsran/srsRAN_Project/discussions)** — GitHub Discussions for the srsRAN Project\n- **[OpenAirInterface Forum](https://gitlab.eurecom.fr/oai/openairinterface5g/-/issues)** — OAI issue tracker and community support\n- **[Reddit r/RTLSDR](https://www.reddit.com/r/RTLSDR/)** — Active SDR community covering cellular scanning and analysis\n- **[Reddit r/cellmapper](https://www.reddit.com/r/cellmapper/)** — Cell tower mapping and analysis community\n\n### IRC and Chat\n\n- **[Osmocom IRC](https://osmocom.org/projects/cellular-infrastructure/wiki/IRC)** — #osmocom on libera.chat; real-time support for Osmocom tools\n- **[DEF CON RF Village](https://rfvillage.org/)** — Annual RF hacking community track at DEF CON\n\n### Notable Researchers and Organizations to Follow\n\n| Name/Organization | Focus Area | Link |\n|-------------------|------------|------|\n| **Syed Rafiul Hussain** | 5G/LTE protocol security, baseband fuzzing | [Website](https://syed-rafiul-hussain.github.io/) |\n| **Imtiaz Karim** | 5GReasoner, LTE noncompliance, cellular formal verification | [Website](https://www.imtiazkarim.net/) |\n| **KAIST SysSec Lab** | LTE/5G core network security | [Website](https://syssec.kaist.ac.kr/) |\n| **SEEMOO Lab (TU Darmstadt)** | iOS baseband, IMSI catcher detection | [GitHub](https://github.com/seemoo-lab) |\n| **ASSET Research Group** | 5G NR fuzzing (5GHOUL, SNI5GECT) | [Website](https://asset-group.github.io/) |\n| **cemaxecuter** | DragonOS, WarDragon, Ransack cellular survey tools | [Twitter](https://twitter.com/cemaxecuter) / [Website](https://cemaxecuter.com/) |\n| **taszk.io** | Samsung/MediaTek baseband exploits, full-chain RCE | [Website](https://labs.taszk.io/articles/tags/baseband/) |\n| **Google Project Zero** | Baseband vulnerability research, Exynos zero-days | [Blog](https://googleprojectzero.blogspot.com/) |\n| **PentHertz** | RF/wireless security pentesting | [Twitter](https://twitter.com/PentHertz) |\n| **P1 Security** | SS7/Diameter security | [Website](https://www.p1sec.com/) |\n| **EFF** | Surveillance tech, Rayhunter, Crocodile Hunter | [Website](https://www.eff.org/) |\n\n### Conferences and Competitions\n\n- **[DEF CON](https://defcon.org/)** — RF Village, Wireless Village, and main track cellular talks\n- **[Black Hat USA/Europe](https://www.blackhat.com/)** — Regular cellular/baseband research presentations\n- **[OffensiveCon](https://www.offensivecon.org/)** — Baseband exploitation talks and training\n- **[Pwn2Own Ireland](https://www.zerodayinitiative.com/Pwn2OwnIreland2025Rules.html)** — Mobile-focused; $100K for baseband RCE exploits\n- **[CanSecWest](https://www.secwest.net/)** — Baseband and mobile security research presentations\n- **[WiSec](https://wisec.acm.org/)** — ACM Conference on Security and Privacy in Wireless and Mobile Networks\n- **[IEEE S\u0026P / CCS / USENIX Security](https://www.ieee-security.org/TC/SP/)** — Top-tier academic venue for cellular security papers\n- **[HITB](https://conference.hitb.org/)** — Regular telecom security talks\n- **[NDSS](https://www.ndss-symposium.org/)** — Network security including FutureG workshop on 5G/6G\n\n---\n\n## Contributing\n\nFork the repo, add resources with descriptions, verify links are active, and submit a pull request with context on what was added.\n\n## Legal Notice\n\nThis repository is for educational and research purposes only. Users are responsible for complying with all applicable laws and regulations. The maintainers do not endorse or encourage illegal activities.\n\n---\n\n**Last Updated:** August 2026\n**Maintainer:** [@W00t3k](https://github.com/W00t3k)\n\n*Broken links or new resources? Open an issue or submit a PR.*\n","projects_url":"https://awesome.ecosyste.ms/api/v1/lists/w00t3k%2Fawesome-cellular-hacking/projects"}