Recon — Scope the Target
You have an RTL-SDR dongle and a laptop running gr-gsm. Before standing up your rogue cell you need to identify the target network's ARFCN, confirm its MCC/MNC/LAC, and verify a victim device is actively camped on it.
RTL-SDRCheap USB software-defined radio dongle (~$25) that can receive 500 kHz–1.7 GHz — the antenna for all of this.
gr-gsmGNU Radio-based toolkit that decodes live GSM air frames from an RTL-SDR into readable packets.
ARFCNAbsolute Radio Frequency Channel Number — a number that maps to a specific GSM frequency pair (uplink + downlink).
MCC / MNCMobile Country Code / Mobile Network Code — together they uniquely identify the carrier (e.g. 310-260 = T-Mobile US).
LACLocation Area Code — groups nearby cells into a zone; phones page on the LAC, not the individual cell.
Step 1.1 · Scan GSM-900 with kalibrate-rtl
Use kal to scan the GSM-900 band and find active channels. The -g 40 flag sets RTL-SDR gain to 40 dB.
kal -s GSM900 -g 40
kal (kalibrate-rtl) sweeps each ARFCN and reports received power. The strongest channel is your target — it has the most subscriber traffic and is easiest to impersonate convincingly. Why 40 dB? RTL-SDR dongles let you set tuner gain from ~0–50 dB. Too low and weak cells vanish into the noise floor; too high and the amplifier saturates, smearing adjacent channels together. 40 dB is a reliable starting point for GSM-900 in most environments — adjust down if you're next to a tower, up if you're getting poor results outdoors.
Step 1.2 · Decode BCCH with grgsm_scanner
Tune to ARFCN 51 and decode its Broadcast Control Channel to pull the full network identity.
grgsm_scanner -b GSM900
grgsm_scanner (part of gr-gsm) decodes the BCCH System Information blocks. This gives you the exact MCC, MNC, LAC, and Cell ID your rogue BTS must advertise to look legitimate.
Step 1.3 · Monitor paging channel
Confirm a target handset is actively camped on ARFCN 51 by watching for paging messages. First start the live monitor, then capture with tshark.
grgsm_livemon -f 940.2e6
tshark -i lo -f 'udp port 4729' -Y 'gsm_a.rr' -c 5
TMSI paged: 0xA4F2E1B3 — victim device is active and nearby.
grgsm_livemon decodes the air frames and forwards them as GSMTAP packets to UDP 127.0.0.1:4729. tshark then filters those for RR (Radio Resource) messages — paging requests include the TMSI of every device the network is trying to reach. TMSI (Temporary Mobile Subscriber Identity) is a short rotating alias the network assigns to hide the permanent IMSI over the air — but it still uniquely identifies a device within a location area, so a repeating TMSI tells you exactly who's nearby.
Deploy — Rogue Cell & Force Attach
Stand up a rogue BTS broadcasting the same MCC/MNC as the legitimate network at higher power. Then suppress the victim's connection to legitimate cells so the handset falls back to your 2G rogue cell.
Step 2.1 · Stand up rogue BTS
Broadcast a GSM cell with the legitimate network's identifiers but much stronger signal.
bts --up --mcc 310 --mnc 260 --arfcn 51 --power 43
Received signal = TX power − ~84 dB path loss. Your cell must arrive stronger than the real tower at -78 dBm for the phone to reselect. At 43 dBm TX: 43 − 84 = -41 dBm — stronger wins.
Step 2.2 · Suppress higher RATs
Jam LTE/5G bands so the victim's phone has no choice but 2G.
rfblock --bands lte,nr
--suppress is a teaching abstraction. Real-world bidding-down is subtler; this compresses the mechanic for the lab.
Step 2.3 · Wait for victim to attach
Monitor your rogue BTS for inbound attach attempts.
bts --monitor
IMSI: 310260741852963 — victim attached.
Intercept — Steal the OTP
The victim's phone is now attached to your rogue cell with A5/0 (null cipher). SMS traffic flows in cleartext through your equipment. Arm the interceptor and capture the authentication OTP the victim's bank is about to send.
Step 3.1 · Arm the SMS interceptor
Target the attached subscriber by IMSI and arm the interceptor.
sms_intercept --imsi 310260741852963
Traffic is in cleartext thanks to A5/0. The next inbound SMS for this subscriber will be captured automatically.
Step 3.2 · Decode the captured SMS
An SMS just arrived. Decode the raw PDU to read it in plaintext. Copy the hex payload from above.
smsdecode 07914151551512F20410D0E2B41C1D06
OTP visible in cleartext — attack complete.