Rayhunter: Recording PCAPs from Stingrays With a $20 Hotspot

Cooper Quintin (Senior Staff Technologist · EFF), Will Greenberg (Senior Staff Technologist · EFF)

ShmooCon XX (Final) · Day 2 · Build It

Overview

In an era of increasing digital surveillance, the ability to reliably detect sophisticated tools like IMSI catchers—often referred to as Stingrays or cell site simulators—is paramount. This talk, presented by Cooper Quintin and Will Greenberg of the Electronic Frontier Foundation (EFF) at ShmooCon, unveils Ray Hunter, an innovative and remarkably affordable solution for identifying these covert surveillance devices. The project leverages a $20 rooted mobile hotspot, transforming it into a powerful 4G IMSI catcher detector capable of recording raw cellular traffic for in-depth analysis.

Watch on YouTube

Visual summary for Rayhunter: Recording PCAPs from Stingrays With a $20 Hotspot by Cooper Quintin, Will Greenberg
Visual summary for Rayhunter: Recording PCAPs from Stingrays With a $20 Hotspot by Cooper Quintin, Will Greenberg

Key moments

  1. 0:00 Introduction to Stingrays and the detection problem
  2. 2:00 Challenges in early Stingray detection attempts
  3. 2:50 Three key goals for Stingray research
  4. 3:20 Who uses cell site simulators and how often
  5. 4:40 Technical overview of 4G Stingray attacks
  6. 5:20 Essential cellular technology concepts explained
  7. 6:40 Key attack vectors in 4G: RRC and NAS

Rayhunter: Recording PCAPs from Stingrays With a $20 Hotspot

Speakers: Cooper Quintin, Senior Staff Technologist, EFF; Will Greenberg, Staff Technologist, EFF

Conference: ShmooCon

YouTube: https://www.youtube.com/watch?v=-_jUZBMeU5w

Overview

In an era of increasing digital surveillance, the ability to reliably detect sophisticated tools like IMSI catchers—often referred to as Stingrays or cell site simulators—is paramount. This talk, presented by Cooper Quintin and Will Greenberg of the Electronic Frontier Foundation (EFF) at ShmooCon, unveils Ray Hunter, an innovative and remarkably affordable solution for identifying these covert surveillance devices. The project leverages a $20 rooted mobile hotspot, transforming it into a powerful 4G IMSI catcher detector capable of recording raw cellular traffic for in-depth analysis.

The significance of Ray Hunter stems from the pervasive and often opaque use of IMSI catchers by government agencies, law enforcement, and even criminal elements. These devices intercept cellular communications, enabling everything from location tracking and identity harvesting to the delivery of malware and targeted phishing attacks. Traditional detection methods have proven either too expensive, too complex, or outdated in the face of modern 4G and 5G native IMSI catchers. Ray Hunter democratizes this critical detection capability, offering an accessible tool for journalists, activists, human rights defenders, and the general public to monitor their local cellular environments for suspicious activity.

The EFF's work not only provides a tangible tool but also sheds light on the evolving tactics of IMSI catchers, particularly the "wallet inspector" attack. By focusing on specific, non-standard behaviors in the 4G protocol stack, Ray Hunter offers a more accurate and robust detection mechanism than its predecessors. This article will delve into the motivations behind the project, the technical intricacies of its design, the key findings from simulated and real-world testing, and the crucial defensive implications for anyone concerned about cellular surveillance.

Background

▶ Watch: Introduction to Stingrays and the detection problem (0:00)

The genesis of the Ray Hunter project traces back to 2016, when Cooper Quintin was alerted by "Water protectors" protesting an oil pipeline in Mandan, North Dakota, who suspected the presence of cell site simulators. His initial attempts to detect these devices using off-the-shelf apps like Android IMSI Catcher Detector, SnoopSnitch, and Darshak, or even more advanced Software Defined Radios (SDRs), proved frustrating. The apps generated numerous, often uninterpretable alerts and false positives, while SDRs required specialized knowledge to analyze raw radio spectrum traces. This experience highlighted a critical gap: the lack of accessible, reliable tools for detecting modern IMSI catchers.

Driven by a commitment to defending First Amendment rights and combating digital surveillance, the EFF established three core goals: first, to quantify the prevalence of cell site simulator use, especially during protests; second, to understand the attack vectors employed by modern 4G IMSI catchers; and third, to develop a dependable detection method. Evidence of IMSI catcher deployment is substantial and varied: foreign spies have been detected using them in Washington D.C. and near the White House; cyber mercenaries like NSO Group leverage them for malware delivery; and law enforcement agencies, including ICE and DHS, reportedly use dozens of these devices hundreds of times annually. Even local police departments, such as Santa Barbara and Fontana, California, reported hundreds of uses (231 in Santa Barbara in 2017, 116 in 2022), far exceeding the plausible number of severe crimes requiring such advanced tools. Furthermore, criminals have been caught using rudimentary IMSI catchers for SMS phishing scams, as seen in a notable incident in Paris.

Understanding how modern 4G IMSI catchers operate required a deep dive into cellular technology. Cooper and his colleague Yamna conducted extensive research, culminating in the white paper "Got to Catch Them All," which detailed various 4G attack methods. The fundamental cellular architecture involves User Equipment (UE, or phone) connecting to an eNodeB (base station/tower), which then links to the enhanced packet core for backend services. For detection purposes, the critical interaction is between the UE and the eNodeB, governed by protocols like Radio Resource Control (RRC) for connection negotiation and Non-Access Stratum (NAS) for authentication and service attachment. Despite improvements in 4G over 2G, such as mutual authentication, many critical messages are exchanged and trusted before authentication is fully established. This vulnerability window allows for downgrade attacks, where a 5G connection can be forced to 4G, and then further to 2G, making older, less secure protocols exploitable.

Previous detection efforts primarily fell into two categories: app-based solutions, which were cheap but offered limited data and high false positives, and radio-based solutions (like Sitch, OverWatch, or Seaglass), which provided better, lower-level data but were expensive, complex to set up, and often required specialized hardware like SDRs. A critical flaw in nearly all prior work was its focus on 2G networks, which are now largely obsolete. Modern IMSI catchers, such as those from KW (now part of Jacob's Technology) or formerly L3 Harris, are 4G native, rendering 2G-centric detectors ineffective. The EFF's own earlier project, Crocodile Hunter, attempted to use a $400-500 BladeRF SDR to emulate a phone and detect suspicious towers. While it could identify towers not in open-source databases, the approach suffered from high costs, setup complexity, and an abundance of false positives due to incomplete data and the legitimate appearance of new towers (e.g., femtocells, Cells on Wheels). This led the team back to the drawing board, seeking a more affordable, user-friendly, and accurate solution for the 4G landscape.

Key Findings

▶ Watch: Three key goals for Stingray research (2:50)

The development of Ray Hunter represents a significant leap forward in affordable IMSI catcher detection, directly addressing the limitations of prior work. The most impactful finding was the identification and successful implementation of a detection strategy centered around a $20 mobile hotspot, specifically the Orbic device. This choice drastically lowered the barrier to entry, making advanced 4G surveillance detection accessible to a much broader audience beyond security professionals. The Orbic's readily rootable Qualcomm baseband chip proved to be a critical enabler, exposing the Qualcomm diag protocol—a treasure trove of raw cellular signaling data previously underutilized in accessible detection tools.

A pivotal contribution of Ray Hunter is the refinement of heuristics, particularly the discovery and validation of the "wallet inspector" attack. This specific attack pattern involves an IMSI catcher (acting as a fake tower) sending an identity request to a phone, asking for its IMSI (International Mobile Subscriber Identity). Upon receiving the IMSI from the phone in an identity response, the fake tower immediately kicks the phone off its network, forcing it back to a legitimate tower. Crucially, the EFF team's extensive testing and collaboration with Cape (a secure mobile company) demonstrated that this sequence of events is highly anomalous in legitimate cellular network operations. While a brief, legitimate IMSI request might occur when a device first powers on after a long period, the "wallet inspector" pattern, especially mid-session, is a strong indicator of an IMSI catcher attempting to harvest subscriber identities.

This "wallet inspector" heuristic proved instrumental in initial field tests, yielding compelling results. While early field deployments along the U.S. border yielded no detections (suggesting low false positives or the vastness of the area), subsequent re-analysis of previously collected data with the refined heuristic uncovered suspicious activity. A Ray Hunter device deployed at the Democratic National Convention (DNC) initially found nothing. However, a re-scan of the data using the new "wallet inspector" heuristic revealed a single instance of the attack near a hotel housing delegates. The device, using an AT&T SIM, was connected to an AT&T tower before, during, and after the attack, indicating no legitimate network change that would justify the IMSI request and subsequent kick-off. Similarly, data collected during a previous ShmooCon along Washington D.C.'s embassy row, initially deemed clear, showed a sequence of highly suspicious events upon re-analysis. These included towers sending location area updates designed to trick the phone into believing it had moved hundreds of miles, followed by an identity request/response, a "UE identity cannot be derived" message, and then a kick-off from the tower. Although the exact embassy location was lost, the pattern strongly suggested IMSI catcher activity in a high-value surveillance area. These findings underscore the efficacy of the "wallet inspector" heuristic and the power of retrospective analysis using the raw data captured by Ray Hunter.

Technical Deep Dive

▶ Watch: Who uses cell site simulators and how often (3:20)

The technical foundation of Ray Hunter is built upon the Orbic mobile hotspot, an inexpensive device that the EFF team discovered could be easily rooted. This rooting process unlocks the full potential of its Qualcomm baseband chip, a well-understood component in the world of reverse engineering. The Orbic device runs a modified version of Android, which, crucially for Ray Hunter, exposes the /dev/diag file. This file serves as the gateway to the Qualcomm diag protocol, an undocumented but thoroughly reverse-engineered diagnostic interface that provides unparalleled access to low-level cellular signaling data.

Ray Hunter's software, written in Rust, interacts with this /dev/diag file. Rust was chosen for its performance characteristics, which are vital given the Orbic's limited hardware resources, and for its memory safety. The core functionality involves sending specific ioctl commands to /dev/diag to enable logging of desired radio frames, such as RRC (Radio Resource Control) and NAS (Non-Access Stratum) messages. Once logging is enabled, the Ray Hunter software continuously reads the raw binary data stream from /dev/diag. This raw data is then saved in two primary formats:

  1. QMDL files: These are Qualcomm's native diagnostic log files, essentially a raw dump of the bytes received from the /dev/diag interface. The brilliance of storing data in QMDL is that it acts as an "upstream source of truth." Even if Ray Hunter's on-device parsing or heuristics are rudimentary at the time of recording, the QMDL file preserves the complete diagnostic information. This allows for retrospective analysis, where new or improved heuristics can be run against old data, effectively re-evaluating past recordings for previously undetected threats.
  2. PCAP files: The decoded frames are also written to standard pcap files. This format is universally recognized by network analysis tools like Wireshark, which includes built-in dissectors for LTE data. This means that users can easily open the pcap files on their laptops and visually inspect the cellular traffic without needing specialized tools beyond Wireshark.

The user interface of Ray Hunter is designed for simplicity and clarity. On the Orbic device itself, a discreet green line at the top of the screen indicates normal operation. If suspicious activity is detected, this line turns red. This visual cue is achieved by directly writing arbitrary RGB values to the device's framebuffer. For more detailed analysis, users can connect a laptop to the Orbic's Wi-Fi hotspot and access a web server hosted on the device. This web UI, while presented in a minimalist JSON format (humorously noted by the speakers as "dumping Json into a pre-tag"), lists all recordings and provides direct links to download the corresponding pcap and qmdl files.

Parsing the captured cellular messages is a complex task. RRC messages are well-defined using ASN.1 (Abstract Syntax Notation One), a formal grammar for data serialization. This allowed the EFF team to generate a parser for RRC messages, which, despite being over 10,000 lines of code, enables on-device parsing and heuristic application directly in Rust. However, NAS messages present a greater challenge. They are formalized in csn1, described as "ASN.1's terrible cousin," lacking robust tooling for parser generation. Consequently, a full NAS parser has not yet been implemented in Rust for on-device execution. Instead, the team currently relies on py_crate, a Python package, for offline NAS parsing on a laptop. A limited on-device NAS parser for the specific "wallet inspector" attack was developed, but a comprehensive solution remains a goal.

Heuristics in Ray Hunter are implemented using a Rust trait, allowing for modular and extensible detection logic. Any new heuristic can implement this trait, providing a user-friendly name and description, and then its analyze_information_element method is invoked for every frame. The method returns an Event, which can be an informational log or a warning with an associated severity.

Key heuristics developed include:

  • Downgrade Attack: Detects attempts by a fake tower to force a phone to a less secure 2G network. While conceptually a strong attack, the current heuristic has not yet observed this in the wild, partly because it only checks for one of multiple downgrade methods.
  • Null Cipher Check: Identifies instances where a tower instructs a phone to use a null cipher, effectively disabling encryption. This is considered highly suspicious and has not been observed in legitimate traffic.
  • IMSI Attach Message: Initially, the team investigated various scenarios where a phone might send its IMSI. Paging messages with IMSIs were found to occur legitimately for location tracking. Similarly, a phone promiscuously attempting to attach to any available tower with its IMSI (e.g., when out of range of its home network, like a T-Mobile user) also happens legitimately. These led to high false positives. The breakthrough was the "Wallet Inspector Attack" heuristic: a specific sequence where an identity request for the IMSI is followed by an identity response, and then the tower immediately kicks the phone off. This behavior is considered highly indicative of an IMSI catcher, with the only known false positive being the very first few packets after a device has been powered on after several days, where a legitimate network might request the IMSI if it doesn't recognize the IMEI.

The combination of affordable hardware, direct access to low-level diagnostic data, robust Rust-based software, and carefully refined heuristics makes Ray Hunter a powerful and practical tool for 4G IMSI catcher detection.

Demo / Proof of Concept

▶ Watch: Essential cellular technology concepts explained (5:20)

The efficacy of Ray Hunter was validated through a combination of simulated attack environments and real-world field testing, providing crucial proof of concept for its detection capabilities.

For simulated attack testing, the EFF collaborated with Cape, a secure mobile company, who generously built and operated an IMSI catcher within their office environment. This controlled setting allowed the Ray Hunter team to rigorously test their detection methods against known attack patterns. Cape successfully demonstrated two key attacks:

  1. Tricking the phone into an attach request: This involved manipulating the phone to initiate an attachment process, which Ray Hunter was able to detect.
  2. The "wallet inspector" attack: Here, the simulated IMSI catcher sent an identity request to the Ray Hunter device, prompting an identity response with the device's IMSI, after which the fake tower immediately disconnected the device. Ray Hunter successfully identified this highly suspicious sequence.

These simulated tests were invaluable. They not only confirmed that Ray Hunter could detect these specific IMSI catcher behaviors but also helped the EFF team identify and mitigate early false positives in their heuristics. This iterative process, using a positive control for the attack, refined Ray Hunter's accuracy and confidence in its core detection logic.

Field testing yielded compelling, albeit sometimes indirect, evidence of IMSI catcher activity:

  • US Border Deployment: An EFF supporter, living and working near the U.S. border, deployed a Ray Hunter device. After extensive testing, no IMSI catcher activity was detected. While this could indicate a lack of false positives, it also highlights the vastness of the border region or potential false negatives that future, more refined heuristics might uncover. The QMDL files from this deployment remain available for future re-analysis.
  • Democratic National Convention (DNC): D. Mator of Wired took a Ray Hunter device to the DNC. Initial analysis with early heuristics yielded no findings. However, a re-analysis conducted more recently with the newly developed "wallet inspector" heuristic found a single instance of the attack. The device, equipped with an AT&T SIM, was connected to a legitimate AT&T tower before, during, and after the attack. The detection showed the fake tower requesting the device's IMSI, receiving it, and then kicking the device off—a sequence with no legitimate network explanation. While not a "smoking gun," the EFF considers this "pretty strong evidence" of an IMSI catcher operating near a hotel where delegates were staying, though the operator's identity (government, espionage, or other) remains unknown.
  • Washington D.C. Embassy Row (ShmooCon): During a previous ShmooCon, Andy Cara (a friend of the EFF team) deployed a Ray Hunter device along embassy row in Washington D.C. Similar to the DNC data, initial analysis with older heuristics showed no activity. However, a re-analysis with the "wallet inspector" heuristic revealed a highly suspicious event. This involved multiple location area updates being sent by surrounding towers, designed to trick the phone into thinking it had rapidly moved hundreds of miles and needed to reconfigure. This was followed by an identity request, an identity response with the IMSI, a "UE identity cannot be derived" message, and then the device being kicked off the tower. The proximity to embassies makes this finding particularly significant, aligning with potential state-sponsored surveillance, though the exact embassy and location data were unfortunately lost.

These real-world detections, particularly the "wallet inspector" attack at high-profile locations, underscore Ray Hunter's ability to identify previously undetected IMSI catcher activity using its novel heuristics and affordable hardware.

Defensive Implications

▶ Watch: Key attack vectors in 4G: RRC and NAS (6:40)

The Ray Hunter project offers crucial defensive implications for individuals, civil society organizations, and the broader security community facing the threat of IMSI catchers.

For individuals at risk, Ray Hunter provides an unprecedented level of accessibility to advanced surveillance detection. The ability to purchase an Orbic mobile hotspot for approximately $20 from Amazon, download an install script from GitHub, and then simply carry the device (e.g., in a backpack or pocket) transforms passive vulnerability into active monitoring. Users can periodically check the device's screen for the red line indicating suspicious activity or access the web UI for more detailed information and to download pcap and qmdl files. While the ultimate advice from Cooper's five-year-old son—"Dad, why don't you just tell those hackers to turn off their phones?"—is amusingly simple, Ray Hunter offers a more practical, albeit complex, alternative.

For journalists, activists, human rights defenders, and researchers, Ray Hunter is a game-changer. The qmdl file format, which captures raw diagnostic data, is particularly significant. It acts as an immutable "source of truth" for any recording, allowing future re-analysis with new or improved heuristics. This means that even data collected years ago can be re-examined as the understanding of IMSI catcher tactics evolves, potentially uncovering previously missed threats. The project's open-source nature (available on GitHub) encourages community contributions, fostering a collaborative environment for developing new heuristics and improving detection accuracy. This democratized approach to data collection is vital for understanding the true prevalence and methods of IMSI catcher deployment, especially in communities and countries where such surveillance is rampant but often unrecorded.

More broadly, Ray Hunter highlights critical vulnerabilities in existing 4G and 5G cellular network protocols, particularly the susceptibility to downgrade attacks and unauthenticated IMSI inspection (the "wallet inspector" attack). The project serves as a concrete demonstration that, despite advancements, the cellular stack still contains weaknesses that can be exploited by relatively unsophisticated (or highly sophisticated but using basic techniques) adversaries. This information empowers the security community to advocate for stronger, more resilient cellular network security standards that prevent these types of information disclosures and protocol manipulations.

The EFF team openly invites collaboration, seeking help from telecom experts to develop more robust heuristics, from UX experts to refine the user interface for non-technical users, and from communities interested in deploying and testing these devices. By empowering more people with the tools and knowledge to detect IMSI catchers, Ray Hunter contributes significantly to countering pervasive digital surveillance and protecting fundamental rights.

Key Takeaways

  • Affordable and Accessible Detection: Ray Hunter transforms a $20 Orbic mobile hotspot into a powerful 4G IMSI catcher detector, democratizing access to advanced surveillance detection capabilities for journalists, activists, and the public.
  • "Wallet Inspector" Attack Heuristic: The project identified and validated a highly suspicious cellular behavior—a tower requesting a device's IMSI and immediately kicking it off—as a strong indicator of an IMSI catcher, rarely seen in legitimate network operations.
  • Leveraging Qualcomm Diag Protocol: Ray Hunter effectively utilizes the previously undocumented Qualcomm diag protocol via the /dev/diag file, providing unparalleled access to low-level cellular signaling data for precise analysis.
  • Retrospective Analysis Capability: The use of qmdl files to store raw diagnostic data enables re-analysis of past recordings with new or improved heuristics, allowing for the discovery of previously undetected IMSI catcher activity.
  • Real-World Validation: Field testing, including re-analysis of data from the DNC and Washington D.C. embassy row, uncovered compelling evidence of IMSI catcher activity, validating Ray Hunter's effectiveness in real-world scenarios.
  • Open-Source and Community-Driven: The project is open-source and actively seeks contributions from telecom experts, UX designers, and at-risk communities to enhance its heuristics, usability, and widespread deployment for comprehensive data collection on IMSI catcher prevalence.

About the Speaker(s)

Cooper Quintin is a Senior Staff Technologist at the Electronic Frontier Foundation (EFF), where he has dedicated over a decade to defending digital rights. His work at EFF spans a wide range of critical areas, including the development of privacy tools like Privacy Badger, investigating state-sponsored malware, analyzing street-level surveillance technologies, and contributing to the Threat Lab project aimed at protecting at-risk individuals from digital surveillance. Cooper's expertise in phone technology, particularly in countering IMSI catchers, forms the backbone of the Ray Hunter project.

Will Greenberg is also a Staff Technologist at the EFF, having recently been promoted to Senior Staff Technologist as of the week of the talk. His primary focus at the EFF involves investigating the data broker industry through projects like C-BOT and researching police surveillance on the street and within car control systems. Ray Hunter marks Will's first time speaking at a hacker conference, showcasing his significant contributions to the project's technical development, particularly in the Rust-based software implementation and UI design.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This talk presents a genuinely clever and highly impactful approach to detecting IMSI catchers (Stingrays) on 4G networks. Instead of relying on expensive SDR setups, the EFF team leveraged a $20 rooted mobile hotspot and the Qualcomm diag protocol to create Ray Hunter, an accessible tool for journalists and activists. While some heuristics are still maturing, the identification of the "wallet inspector" attack and its real-world detection near politically sensitive locations demonstrates concrete, actionable research that directly addresses a critical surveillance threat.

Heather Calloway (CISO) — STRONG ACCEPT

The Rayhunter project presents a remarkably effective and accessible solution for detecting IMSI catchers, addressing a critical gap in countering sophisticated mobile surveillance. By leveraging an inexpensive mobile hotspot and a novel 'wallet inspector' heuristic, it democratizes a capability previously limited by cost and complexity. While not a tool for every CISO's daily operations, it provides crucial, actionable intelligence for protecting high-value individuals, sensitive operations, and understanding the evolving landscape of state-sponsored or targeted surveillance. This work delivers real-world defensive value and informs the broader institutional understanding of mobile risk.

→ Top-rated talks at ShmooCon XX (Final)

All talks from ShmooCon XX (Final)