The Scale of IMSI Catcher Use
ICE and DHS used their IMSI catchers almost 5,000 times between 2012 and 2019. Fontana, California, used theirs 300 times in 2022-2023. Local law enforcement agencies across the US own at least one. Cooper Quintin flew to the Dakota Access Pipeline protests in 2016 with apps and SDRs but found nothing. He concluded that detection needed a simpler, cheaper approach.
How 4G IMSI Catchers Exploit Unauthenticated Messages
4G introduced mutual authentication between phone and network. But RRC and NAS messages are sent and trusted before authentication completes. These unauthenticated setup messages are the weak spot. Downgrade attacks force phones to 2G, where no network authentication exists. 5G does not fix the problem: companies like Group 2000 sell tools to turn off 5G across an area.
Ray Hunter: A $20 Detection Tool
Will Greenberg described Ray Hunter as Crocodile Hunter 2.0. The target device is an Orbit mobile hotspot, running Android on a Qualcomm baseband, costing about $20. Ray Hunter enables the DIAG diagnostic protocol to capture raw radio data frames. It writes QMDL files and pcap files, then parses RRC and NAS messages into Rust structures. Heuristics analyze the messages for anomalies. The web UI shows warnings and lets users download traces for expert review.
Four Categories of Heuristics for Few False Positives
Cooper Quintin outlined four heuristic categories. 2G downgrade detection flags any tower advertising 2G at higher priority than 4G. Null cipher use should only occur during 911 calls. Missing neighbor cells indicate lazy operator configuration. Identity requests for IMSI or IMEI without authentication are suspicious, especially on a home network. The team tested these against a commercial law enforcement IMSI catcher in a lab. Ray Hunter emitted four alerts: three for missing neighbor cells and one for disconnect after identity request.
Field Results: Chicago, Toronto, Los Angeles
In downtown Chicago, a user received dozens of identity requests and disconnects over an hour, matching the lab-tested commercial catcher behavior. In Toronto, a tower triggered almost every heuristic: tracking area update, IMSI request, null cipher suggestion, and a 2G downgrade. In Los Angeles, a null cipher request appeared at night, the first such US report. No alerts came from No Kings protests or Minneapolis ICE operations.
Next Steps and How to Contribute
Future work includes a GUI installer so no terminal is needed, a companion app for GPS correlation and notifications, better signatures for known attacks, international device support, and 5G analysis. The project needs volunteers to port Ray Hunter to other Qualcomm devices, write heuristics, and collect field data. Users can send QMDL files even if heuristics are buggy; they can be rescanned later.
Q&A
Can the devices automatically report to a phone? Will Greenberg said NTFY.sh notification support exists if the device has a data plan, and Wi-Fi client mode and auto-upload are planned. βΆ 44:03
What does a warrant for IMSI catcher use entitle? Cooper Quintin answered that warrants should be tightly constrained to a specific person and area, but the exact content of such warrants is kept secret. βΆ 45:07
Notable Quotes
I had no idea what I was doing. Cooper Quintin Β· βΆ 3:38
journalists donβt want to compile C. Cooper Quintin Β· βΆ 13:07
this is exactly the same behavior as we saw from the commercial MC catcher in our lab. Cooper Quintin Β· βΆ 33:56
first time Iβve seen a null cipher used in the US Cooper Quintin Β· βΆ 36:14
Dad, why donβt you just tell those hackers to turn off their phones? Cooper Quintin Β· βΆ 43:06
Key Takeaways
- Ray Hunter detects 4G IMSI catchers using $20 hardware and heuristics on unauthenticated messages.
- Field tests against a commercial catcher produced four alerts; 23 of 160 field reports are highly suspicious.
- 2G downgrade, null cipher, missing neighbor cells, and identity request heuristics flag real IMSI catcher behavior.
About the Speaker(s)
Cooper Quintin is a Senior Security Researcher at the EFF Threat Lab. He has worked on projects such as Privacy Badger, Canary Watch, and analysis of state sponsored malware, IMSI catchers, and other digital attacks on activists, journalists, and human rights defenders.