● Section 2 — Rogue BTS & OTP Theft
Mission Stand up a rogue BTS and intercept a live OTP. We start with passive recon — using nothing but a cheap RTL-SDR dongle — to harvest the exact cell identifiers the real network broadcasts. Those values feed directly into the BTS configuration in Stage 2.

2G Attack Playbook

Recon — Scope the Target

You have an RTL-SDR dongle and a laptop running gr-gsm. Before standing up your rogue cell you need to identify the target network's ARFCN, confirm its MCC/MNC/LAC, and verify a victim device is actively camped on it.
RTL-SDRCheap USB software-defined radio dongle (~$25) that can receive 500 kHz–1.7 GHz — the antenna for all of this.
gr-gsmGNU Radio-based toolkit that decodes live GSM air frames from an RTL-SDR into readable packets.
ARFCNAbsolute Radio Frequency Channel Number — a number that maps to a specific GSM frequency pair (uplink + downlink).
MCC / MNCMobile Country Code / Mobile Network Code — together they uniquely identify the carrier (e.g. 310-260 = T-Mobile US).
LACLocation Area Code — groups nearby cells into a zone; phones page on the LAC, not the individual cell.
Step 1.1 · Scan GSM-900 with kalibrate-rtl
Use kal to scan the GSM-900 band and find active channels. The -g 40 flag sets RTL-SDR gain to 40 dB.
kal -s GSM900 -g 40
kal (kalibrate-rtl) sweeps each ARFCN and reports received power. The strongest channel is your target — it has the most subscriber traffic and is easiest to impersonate convincingly. Why 40 dB? RTL-SDR dongles let you set tuner gain from ~0–50 dB. Too low and weak cells vanish into the noise floor; too high and the amplifier saturates, smearing adjacent channels together. 40 dB is a reliable starting point for GSM-900 in most environments — adjust down if you're next to a tower, up if you're getting poor results outdoors.
Step 1.2 · Decode BCCH with grgsm_scanner
Tune to ARFCN 51 and decode its Broadcast Control Channel to pull the full network identity.
grgsm_scanner -b GSM900
grgsm_scanner (part of gr-gsm) decodes the BCCH System Information blocks. This gives you the exact MCC, MNC, LAC, and Cell ID your rogue BTS must advertise to look legitimate.
Step 1.3 · Monitor paging channel
Confirm a target handset is actively camped on ARFCN 51 by watching for paging messages. First start the live monitor, then capture with tshark.
grgsm_livemon -f 940.2e6
tshark -i lo -f 'udp port 4729' -Y 'gsm_a.rr' -c 5
TMSI paged: 0xA4F2E1B3 — victim device is active and nearby.
grgsm_livemon decodes the air frames and forwards them as GSMTAP packets to UDP 127.0.0.1:4729. tshark then filters those for RR (Radio Resource) messages — paging requests include the TMSI of every device the network is trying to reach. TMSI (Temporary Mobile Subscriber Identity) is a short rotating alias the network assigns to hide the permanent IMSI over the air — but it still uniquely identifies a device within a location area, so a repeating TMSI tells you exactly who's nearby.

Deploy — Rogue Cell & Force Attach

Stand up a rogue BTS broadcasting the same MCC/MNC as the legitimate network at higher power. Then suppress the victim's connection to legitimate cells so the handset falls back to your 2G rogue cell.
Step 2.1 · Stand up rogue BTS
Broadcast a GSM cell with the legitimate network's identifiers but much stronger signal.
bts --up --mcc 310 --mnc 260 --arfcn 51 --power 43
Received signal = TX power − ~84 dB path loss. Your cell must arrive stronger than the real tower at -78 dBm for the phone to reselect. At 43 dBm TX: 43 − 84 = -41 dBm — stronger wins.
Step 2.2 · Suppress higher RATs
Jam LTE/5G bands so the victim's phone has no choice but 2G.
rfblock --bands lte,nr
--suppress is a teaching abstraction. Real-world bidding-down is subtler; this compresses the mechanic for the lab.
Step 2.3 · Wait for victim to attach
Monitor your rogue BTS for inbound attach attempts.
bts --monitor
IMSI: 310260741852963 — victim attached.

Intercept — Steal the OTP

The victim's phone is now attached to your rogue cell with A5/0 (null cipher). SMS traffic flows in cleartext through your equipment. Arm the interceptor and capture the authentication OTP the victim's bank is about to send.
Step 3.1 · Arm the SMS interceptor
Target the attached subscriber by IMSI and arm the interceptor.
sms_intercept --imsi 310260741852963
Traffic is in cleartext thanks to A5/0. The next inbound SMS for this subscriber will be captured automatically.
Step 3.2 · Decode the captured SMS
An SMS just arrived. Decode the raw PDU to read it in plaintext. Copy the hex payload from above.
smsdecode 07914151551512F20410D0E2B41C1D06
OTP visible in cleartext — attack complete.

Signal View

Idle

Attack Console

Type help
Flags: none yet
root@rogue-bts:~#
Investigate — Rogue BTS Incident
A SOC alert flagged anomalous GSM radio traffic near a monitored location. An RF sensor captured a short packet trace before the rogue transmitter went dark. Your job: analyze the PCAP, identify what subscriber data was exposed, determine what cipher the attacker forced, and recover the intercepted OTP. Click any packet row to inspect its fields, then type your answers directly into the Investigation Checklist.

PCAP — capture_rbs_incident.pcapng

13 packets · GSM/A · GSM/SMS · TCP
No. Time Source Destination Protocol Len Info
Click a packet row to inspect its fields

Investigation Checklist

0 / 4 complete
What is the victim's IMSI?
Show hint
the device sends it when it registers
What cipher was negotiated?
Show hint
set during connection setup
What received signal strength did the rogue BTS report?
Show hint
check the initial channel assignment
What OTP was intercepted in cleartext?
Show hint
it's in the SMS layer