
Awesome-Cellular-Hacking
A comprehensive curated list of resources for 2G/3G/4G/5G cellular security research and analysis
This repository consolidates community knowledge in the cellular security space, including exploits, research papers, tools, and educational resources. The goal is to preserve and organize important security research that might otherwise become difficult to find.
Disclaimer: This information is intended for educational and defensive security research purposes only. Use responsibly and in compliance with applicable laws and regulations.
New to cellular security research? This section outlines the recommended path for building foundational skills.
Beginner (passive listening only)
Intermediate (active research lab)
Advanced (protocol fuzzing and baseband research)
uhd_find_devices)How To Build Your Own Rogue GSM BTS For Fun and Profit
Guide to creating a portable GSM BTS for private networks or security testing. Covers technical setup using relatively inexpensive hardware.
How to Create an Evil LTE Twin / LTE Rogue BTS
Tutorial for setting up a 4G/LTE Evil Twin base station using srsRAN and USRP SDR devices.
Practical Attacks Against GSM Networks: Impersonation
Detailed analysis of GSM base station impersonation using SDR and open source tools.
Tutorial: Analyzing GSM with Airprobe and Wireshark
Step-by-step guide for using RTL-SDR to analyze GSM signals with GR-GSM/Airprobe and Wireshark.
GSM/GPRS Traffic Interception for Penetration Testing
NCC Group research on GSM/GPRS interception capabilities for penetration testing engagements.
RANsacked: 100+ Flaws in LTE and 5G Implementations — University of Florida / NC State, Jan 2025
Researchers disclosed 119 vulnerabilities (97 CVEs) across seven LTE and three 5G implementations including Open5GS, Magma, OpenAirInterface, Athonet, SD-Core, srsRAN. Every flaw can be used to persistently disrupt city-wide cellular communications. Some require no SIM card — a single unauthenticated packet can crash an MME or AMF.
CITesting: Context Integrity Violations in LTE Core Networks — KAIST, ACM CCS 2025 (Distinguished Paper)
KAIST researchers identified a new class of uplink attacks against LTE core networks. Unlike traditional downlink attacks, these work through legitimate base stations and can affect anyone in the same MME coverage area. All four tested implementations (Open5GS, srsRAN, Amarisoft, Nokia) were vulnerable.
Uncovering Hidden Paths in 5G: Protocol Tunneling and Network Boundary Bridging — ACM CCS 2025
New research on exploiting protocol tunneling in 5G networks to cross network boundaries and reach components that should be isolated.
BaseBridge: Over-the-Air and Emulation Testing for Cellular Baseband Firmware — IEEE S&P 2025
Bridges the gap between over-the-air and emulation-based testing for cellular baseband firmware analysis.
5G Network Slicing: Security Challenges, Attack Vectors, and Mitigation — PMC, July 2025
Comprehensive classification of attacks across orchestration, virtualization, and inter-slice communication layers in 5G.
Survey on 5G Physical Layer Security Threats and Countermeasures — MDPI Sensors, 2024
In-depth review of PHY layer attack surface in 4G/5G: jamming, spoofing, eavesdropping, pilot contamination, and current SDR-based research tooling.