Awesome-Cellular-Hacking
Awesome-Cellular-Hacking
https://github.com/W00t3k/Awesome-Cellular-Hacking
Last synced: 12 days ago
JSON representation
-
4G/LTE Cellular Attacks
- BaseSAFE: Baseband SAnitized Fuzzing through Emulation
- Forcing a targeted LTE Cellphone Into an Eavesdropping Network
- Hacking Cellular Networks
- White-Stingray: Evaluating IMSI Catchers Detection Applications
- LTE/LTE-A Jamming, Spoofing, and Sniffing - Assessment and Mitigation
- Using OpenBTS - "Experimental_Security_Assessment_of_BMW_Cars by KeenLab"
- LTE Security β How Good Is It?
- Small Tweaks do Not Help: Differential Power Analysis of MILENAGE Implementations in 3G/4G USIM Cards
- 4G Access Level Security Assessment
- LTE security and protocol exploits
- LTE Recon - (Defcon 23)
- LTE Pwnage: Hacking HLR/HSS and MME CoreNetwork Elements
- Modmobjam - Jam tomorrow, jam yesterday, but also jam today
- WiFi IMSI Catcher
- Demystifying the Mobile Network by Chuck McAuley
- NSA PLAYSET GSM
-
5G Cellular Attacks
-
5G Cellular Attacks (Soon to be updated)
-
π Additional Reading
-
Legal & Regulatory
-
-
βοΈ Attack Vectors
-
5G Security Research
-
LTE/4G Security Research
- LTRACK: Stealthy Mobile Phone Tracking
- Detecting Fake 4G Base Stations
- Paging Storm Attacks against 4G/LTE Networks
- LTE Public Warning System Attacks
- Hacking Public Warning System in LTE
- Analysis of the LTE Control Plane
- Baseband Attacks: Remote Exploitation
- Hiding in Plain Signal: Physical Signal Overshadowing
- LTE Security DisabledβMisconfiguration in Commercial Network
- All The 4G Modules Could Be Hacked
- BaseSAFE: Baseband Fuzzing
-
Radio Jamming Attacks
-
-
Attack Vectors
-
5G Security Research
-
LTE/4G Security Research
- New Vulnerabilities in 4G and 5G Cellular Access Network Protocols
- Full Chain Baseband Exploits - click RCE in baseband and Android runtime
- Unburdened By What Has Been: Exploiting L2 for Baseband RCE on Samsung Exynos - 2023-41111, CVE-2023-41112
-
Overshadowing Attacks (2024-2026)
-
-
Automotive and Industrial Cellular
-
Security Advisories
-
-
π Automotive & Industrial Cellular
-
Security Alerts & Advisories
- V2X Security Research - Vehicle-to-everything communications
- Cellular-V2X Attack Vectors - Automotive cellular security
-
-
Cellular IoT and NB-IoT Security
-
Security Advisories
-
-
π± Cellular IoT & NB-IoT Security
-
Security Alerts & Advisories
- NB-IoT Security Analysis Framework - Narrowband IoT security research
-
-
CERT/Media Alerts
-
Community
-
Conferences and Competitions
- OffensiveCon
- Pwn2Own Ireland - focused; $100K for baseband RCE exploits
- CanSecWest
- NDSS
-
Conferences to Follow
-
IRC and Chat
-
Mailing Lists and Forums
-
Notable Researchers and Organizations to Follow
-
-
π€ Conference Talks
-
Additional Conference Resources
-
Black Hat 2021
-
Black Hat 2022
-
Black Hat 2024
-
DefCon 32 (2024)
-
TROOPERS 2013
-
-
Conference Talks
-
Black Hat Asia 2026
-
Black Hat USA 2025
-
DEF CON 32 (August 2024)
-
DEF CON 33 (August 2025)
- Gateways to Chaos: How We Proved Modems Are a Ticking Time Bomb - Lin "Steven Meow" Yu, Trend Micro
- Hacking Hotspots: Pre-Auth RCE and Arbitrary SMS on 4G/5G Routers
-
OffensiveCon 2025
-
USENIX Security 2023
-
-
Detection and Defense
-
Protection from Stingrays and IMSI Catchers
- Documentation - rayhunter-new-open-source-tool-eff-detect-cellular-spying)
-
-
π‘οΈ Detection & Defense
-
IMSI Catcher Detection & Research
-
π¨ Protection from Stingrays & IMSI Catchers
- CellGuard - **NEW 2024** π₯
- Website & Documentation
- TestFlight Beta
-
-
π Equipment & Hardware
-
Research Equipment Used in "Over The Air Baseband Exploit"
-
-
π Forensics & Investigation
-
Security Alerts & Advisories
- XRY Mobile Forensics - Commercial cellular forensics platform
- Cellebrite UFED - Mobile device extraction tools
- MSAB Cellular Evidence Analysis - Network evidence collection
- NIST Mobile Forensics Guidelines - Mobile device forensics standards
- Cellebrite UFED - Mobile device extraction tools
-
-
Getting Started
-
Key Concepts to Understand First
-
-
π§ Hardware Setup
-
SDR Hardware Options
-
-
π International Research
-
Stingray/IMSI Catchers
- China Mobile Security Research - Chinese cellular security papers
- European Cybersecurity Agency (ENISA) 5G Reports - EU 5G security assessments
- Korean KISA Mobile Security - Korean mobile security research
- Japanese 5G Security Guidelines - Japan cybersecurity strategy
-
-
International Research
-
CVE Resources
-
Stingray / IMSI Catchers
-
-
[JAMMING SPECIFC ATTACKS](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-187.pdf)
-
βοΈ Legal Notice
-
Legal & Regulatory
-
-
Misc
-
π Network Slicing & Edge Security
-
Security Alerts & Advisories
- 5G Network Slicing Attack Research - IEEE research papers
- Multi-Access Edge Computing (MEC) Vulnerabilities - ETSI MEC security specs
- Network Function Virtualization (NFV) Attacks - Virtual network function security
-
-
π Recent CVEs & Updates
-
Stingray/IMSI Catchers
- CVE Database Search - Search for cellular-related vulnerabilities
- Project Zero Cellular Security Research - Google's ongoing mobile security research
- SIMjacker and Simswap Updates - Evolution of SIM-based attacks
-
-
π Recent Updates (2024-2025)
-
Latest Base Station Software & Tools
- LimeNET CrowdCell - in-a-box solution with integrated LimeSDR for small cell deployments
- Amarisoft LTEENB/gNB - grade LTE/5G NR base station software
- DragonOS - based SDR distribution with preinstalled cellular tools
- Magma Core Network
-
-
π’ Private 5G Network Security
-
Security Alerts & Advisories
- O-RAN Security Research - Open RAN security specifications
- Campus 5G Security Assessment - NIST private 5G security guidance
-
-
Private 5G Network Security
-
Recent CVEs and Updates
-
2024-2025 Notable CVEs
- CVE-2023-24033 (Google Project Zero) - to-baseband RCE via malformed SDP in VoLTE/VoWiFi; no user interaction required. Part of 18 zero-day disclosure affecting Pixel 6/7, Galaxy S22, Vivo, and Samsung wearables
- CVE-2024-55568
- CVE-2024-25073
- CVE-2025-58349
- Open5GS CVEs (2024-2025)
-
2026 Notable CVEs
- CVE-2026-21385
- MediaTek March 2026 Bulletin - 2026-20423 through CVE-2026-20445 affecting MT7902, MT7920, MT7921, MT7922, MT7925, MT7927
-
CVE Resources
-
-
Recent Updates (2024-2025)
-
New Research (2025)
- RANsacked: 100+ Flaws in LTE and 5G Implementations
- CITesting: Context Integrity Violations in LTE Core Networks
- Uncovering Hidden Paths in 5G: Protocol Tunneling and Network Boundary Bridging
- BaseBridge: Over-the-Air and Emulation Testing for Cellular Baseband Firmware
- 5G Network Slicing: Security Challenges, Attack Vectors, and Mitigation
- Survey on 5G Physical Layer Security Threats and Countermeasures
-
-
Recent Updates (2024-2026)
-
Base Station Software and Tools (Updated)
- DragonOS - based SDR distro with cellular tools pre-installed; supports RTL-SDR, HackRF, LimeSDR, BladeRF; latest release is DragonOS Noble (24.04). [Website](https://cemaxecuter.com/)
- WarDragon - enhanced cellular survey capabilities; integrates with TAK; includes Ransack for multi-RAT survey
- Ransack - RAT cellular survey/recon platform; unifies LTE/5G NR/GSM/NB-IoT observations from SDRs, Qualcomm phones, and Rayhunter into SQLite with REST API
-
New Research (2024)
-
New Research (2025-2026)
- SNI5GECT: Sniffing and Injecting 5G Traffic Without Rogue Base Stations
- GitHub
- 5Gone: Uplink Overshadowing Attacks in 5G-SA
- Kairos: Timing-Induced Interaction Failures in LTE and 5G Core Networks
- LLFuzz: LLM-Guided Baseband Firmware Fuzzing
- BaseBridge: Over-the-Air and Emulation Testing for Cellular Baseband Firmware
- From Control to Chaos: Formal Analysis of 5G Access Control
- Devilray: Adversarial Model Revealing Blind Spots in Fake Base Station Detection
- GLaDoS: Location-aware Denial-of-Service of Cellular Networks
- Breaking 5G on The Lower Layer
-
-
π Research Papers
-
2024 Research
- 5GBaseChecker Tool Release - Penn State University
-
NDSS 2025
-
-
Research Papers
-
2019-2022
-
2024
-
2025
-
2026
-
-
π Resources
-
Development & Analysis Tools
- RFSec-ToolKit - RF security testing tools
-
Categories
Community
20
Recent Updates (2024-2026)
20
π οΈ Software & Tools
18
π§ Hardware Setup
17
βοΈ Attack Vectors
16
4G/LTE Cellular Attacks
16
Software and Tools
16
Resources
10
π€ Conference Talks
10
Conference Talks
9
Recent CVEs and Updates
8
π Resources
6
π Equipment & Hardware
6
π‘οΈ Detection & Defense
6
Attack Vectors
6
Training and Education
6
Research Papers
6
Recent Updates (2024-2025)
6
π Forensics & Investigation
5
Private 5G Network Security
5
ποΈ Rogue Base Stations
5
π¨ Vulnerability Disclosure
4
SIM Security
4
π‘ Surveillance Technology
4
π Vendor-Specific Research
4
π International Research
4
π°οΈ Satellite-Cellular Integration
4
5G Cellular Attacks (Soon to be updated)
4
π Recent Updates (2024-2025)
4
International Research
3
π Roaming & Interconnect Security
3
π Training & Education
3
Getting Started
3
π Network Slicing & Edge Security
3
π Recent CVEs & Updates
3
π Additional Reading
2
[JAMMING SPECIFC ATTACKS](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-187.pdf)
2
Rogue BTS & CDMA/GSM Traffic Impersonation and Interception
2
SIM Specific Attacks
2
π Automotive & Industrial Cellular
2
5G Cellular Attacks
2
π Research Papers
2
π’ Private 5G Network Security
2
Roaming and Interconnect Security
1
Misc
1
Detection and Defense
1
Vulnerability Disclosure
1
SS7 and Telecom Infrastructure
1
π¬ Testing & Research Methodologies
1
CERT/Media Alerts
1
π± Cellular IoT & NB-IoT Security
1
βοΈ Legal Notice
1
SS7/Telecom Specific
1
Cellular IoT and NB-IoT Security
1
Testing and Research Methodologies
1
Automotive and Industrial Cellular
1
Vendor-Specific Research
1
Sub Categories
Analysis Tools
23
Security Alerts & Advisories
21
Stingray/IMSI Catchers
21
SDR Hardware Options
17
LTE/4G Security Research
14
New Research (2025-2026)
10
Security Advisories
8
Base Station Software
8
Notable Researchers and Organizations to Follow
7
New Research (2024)
7
Research Equipment Used in "Over The Air Baseband Exploit"
6
5G Security Research
6
New Research (2025)
6
Legal & Regulatory
5
Mailing Lists and Forums
5
GSM/CDMA Traffic Impersonation and Interception
5
Lab Environments
5
2024-2025 Notable CVEs
5
Additional Conference Resources
4
SIM Swap Attack Prevention and Detection
4
Latest Base Station Software & Tools
4
Conferences and Competitions
4
Base Station Software and Tools (Updated)
3
CVE Resources
3
Configuration Guides
3
GitHub Collections
3
Conferences to Follow
3
IMSI Catcher Detection & Research
3
Stingray / IMSI Catchers
3
Key Concepts to Understand First
3
π¨ Protection from Stingrays & IMSI Catchers
3
Black Hat 2021
2
OffensiveCon 2025
2
Black Hat USA 2025
2
Development & Analysis Tools
2
Video Tutorials
2
2026
2
2026 Notable CVEs
2
Research Collections
2
DEF CON 33 (August 2025)
2
2024
2
TROOPERS 2013
1
Radio Jamming Attacks
1
Vulnerability Research Tools
1
2019-2022
1
DefCon 32 (2024)
1
Professional Training
1
Development and Analysis Tools
1
Black Hat 2022
1
Black Hat 2024
1
Modern Baseband Fuzzing (2024-2026)
1
SS7 Attack Research
1
Additional Reading
1
Protection from Stingrays and IMSI Catchers
1
2025
1
Black Hat Asia 2026
1
IRC and Chat
1
DEF CON 32 (August 2024)
1
Overshadowing Attacks (2024-2026)
1
USENIX Security 2023
1
2024 Research
1
NDSS 2025
1
Keywords
5g
5
sdr
5
wireless
5
lte
5
5gc
3
3gpp
3
cellular
3
srsran
3
fuzzing
2
baseband
2
srslte
2
open5gs
2
usrp
2
srs
2
core-network
1
ausf
1
amf
1
free5gc
1
n3iwf
1
nrf
1
nssf
1
pcf
1
release15
1
smf
1
udm
1
srsue
1
srsepc
1
srsenb
1
radio
1
limesdr
1
iot
1
hardware
1
hackrf
1
gnuradio
1
communication
1
bladerf
1
samsung
1
gnodeb
1
mec
1
mobile-edge-computing
1
mobile-network
1
ran
1
ue
1
zeromq
1
gprs
1
gsm
1
openbts
1
software-defined-radio
1
ios
1
o-ran
1