Rogue Base Station (Fake BTS)

A rogue base station is unauthorised radio infrastructure operated by an attacker that broadcasts a stronger signal than legitimate cells to attract nearby devices. Once attached, the attacker can perform IMSI capture, force cipher downgrade, inject silent SMS, or relay traffic for interception. Rogue base stations are the operational delivery mechanism for IMSI catchers and continue to threaten 2G and 3G networks; 5G's mutual authentication and SUCI mitigate but do not entirely eliminate the risk where fallback to legacy generations is permitted.

Categories: Radio Access NetworkSignalingIdentity and Subscriber

Rogue Base Station (Fake BTS) in context

The radio access network is where mobile devices attach to the operator's infrastructure. Attacks in this layer include IMSI catching, rogue base stations and downgrade attacks; defenses rest on mutual authentication, integrity-protected signaling and Open RAN supply-chain hygiene.

Signaling protocols carry the control-plane messages that set up calls, register subscribers and route SMS. SS7, Diameter, GTP-C and SIP are the four dominant families, and interconnect exposure of any of them is treated by GSMA as top-tier telecom risk.

To place Rogue Base Station (Fake BTS) in the wider telecom-security picture, review BTS Impersonation (Fake BTS), Cleartext (Plain Text), E911, OFCS, SMS Pumping and UMTS — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.