IMSI Catcher

An IMSI catcher is a fake base station — a radio that impersonates a legitimate cell, attracts nearby handsets to attach to it, and abuses the small set of NAS messages that occur before mutual authentication and ciphering are in place to extract the subscriber's permanent identity (IMSI in 2G/3G/4G, SUPI in 5G), determine their presence at a location, and in some configurations force a downgrade to a weaker cipher so that subsequent traffic can be intercepted or replayed. The same hardware is also sold under the brand name "Stingray" in the law-enforcement market.

The attack works because the UE has to talk to a cell before it can authenticate it. On 2G the network was never authenticated to the UE at all; on 3G/4G the UE authenticates the network via EPS-AKA but only after sending some unprotected NAS messages; on 5G the new SUPI/SUCI concealment scheme (3GPP TS 33.501) closes the long-standing IMSI exposure by encrypting the permanent identifier with the home network's public key before it is sent over the air. A fake base station typically issues an unprotected NAS Identity Request to harvest IMSIs, or pretends not to support strong ciphers to trigger a downgrade to EIA0/EEA0 (4G) or NIA0/NEA0 (5G).

Containment is layered. On the radio side, modern UEs and operator policy refuse null-cipher NAS except in standardised emergency cases, and 5G's SUCI removes the IMSI-in-clear problem at the source. On the network side, the operator combines integrity-mandatory NAS policy, anomaly detection on attach storms, and signalling-side controls that close the SS7/Diameter paths an attacker uses to weaponise the IMSI once captured. See the NAS Security hub for the pre-SMC attack surface, the 5G Security hub for SUPI/SUCI and 5G-AKA, and the SS7 firewall guide for the signalling-side counterparts that block IMSI-to-location and IMSI-to-intercept follow-on attacks.

Frequently asked questions about imsi catcher

What is SUPI and SUCI in 5G, and how do they protect subscriber privacy?

SUPI (Subscription Permanent Identifier) is the permanent subscriber identity in 5G, replacing the IMSI. SUCI (Subscription Concealed Identifier) is an encrypted version of the SUPI transmitted over the air interface, using the home network's public key. This prevents IMSI catching attacks where passive eavesdroppers could previously identify and track subscribers.

What is an IMSI catcher and how does it work?

An IMSI catcher (also called a "Stingray" or fake base station) impersonates a legitimate cell tower to force nearby mobile devices to connect to it. Once connected, the attacker can capture the device's IMSI/IMEI, intercept unencrypted communications, perform man-in-the-middle attacks, and track the device's physical location. 5G's SUCI mechanism partially mitigates this by concealing the permanent identifier.

See all telecom security FAQs

Related glossary terms

Browse the full telecom security glossary

Related comparisons

More on Imsi Catcher

Browse all topic hubs, the Ultimate Guide to Mobile Network Security and the TelcoSec Glossary.