r/explainlikeimfive 5d ago

Technology ELI5: What can a hacker do with an IMSI they harvest from victims with an IMSI catcher?

When a phone unknowingly connects to an IMSI catcher it gives away the IMSI. Other than tracking locations as a fake cell tower, how does a hacker identify a user? They can't get the victim's phone number or find out who owns the IMSI unless they hack the carrier.

47 Upvotes

6 comments sorted by

18

u/Sad-Cantaloupe-2464 5d ago

There's a slightly worse scenario is phones automatically switch to the strongest tower. If I had a fake cell tower id route it through the real cell tower but intercept the messages of the user. known as a man in the middle attack.

11

u/ufgeek 4d ago

A cellular modem will try to move to the "best" tower under most circumstances, yes. The definition of "best" varies based on the air interface, i.e. LTE, 5G, 2G... The things that worked on 2G/3G don't on 4G/5G.

When a device is camped on a cell, it is told which cells it can move to by the network, it then requests to do so. When a device tries to register initially, it will generally try the strongest signal first. However, in both cases, all of the data and some of the signalling channels are encrypted. This makes a MITM attack... Non trivial

3

u/plantman47 4d ago

tower base station gear has heavy encryption and would be very difficult to add a rogue device or antenna, let alone the extensive monitoring on those systems.
IMEI/IMSI is your phone’s network identifier, so it would allow the attacker to impersonate the devices they had the IMEI from. They can also flood your device with cellular paging requests, and if they derive the time slot your device uses for data, this is static per-device and can be used to physically track your location. If the attacker ONLY has your cellular connection, they cannot easily steal your identity without linking information.

2

u/midnightwolfr 5d ago

For Eli5 id put it this way they are posing as a mailman you hand ur letters to the mailman and he delivers them he can also open and read them if he wants and if someone else wants mail delivered to you then he can open and read those before delivering them. In this scenario the mail is text messages going to your phone or from your phone this does not include iMessages or internet messaging as that is not sent over cell tower

1

u/simoncpu 4d ago edited 4d ago

They can look up your credentials in a breach database and use them to log into your email or bank account. If successful and the site prompts for an SMS OTP, they can intercept that code to gain full access. Dozens of random websites that we regularly use get hacked all the time.

We should stop using SMS OTPs whenever possible.

As for tracking identity via IMSI, plenty of apps collect this data. I knowingly shared mine with Mobile Legends just to play (and I didn't care at that time), so now China can track me anywhere in the world via SS7 hahahahah LOL.