HomeSecurityLTE reconnaissance: How to passively map a mobile network for $300

LTE reconnaissance: How to passively map a mobile network for $300

How easy is it today to “read” what’s happening on a local 4G/5G network with equipment worth less than 500 euros? The answer concerns every mobile phone user: with a LimeSDR , a Linux distribution and the open source tool FALCON, anyone can passively map the movement of a mobile tower, see how many devices are connected and what their current load is. This LTE reconnaissance technique is described in a recent article by Hackers-Arise and opens a discussion about the security of the mobile communications infrastructure.

The FALCON (Fast Analysis of LTE on Control channels) tool was developed by researchers at the University of Dortmund in Germany and is an academic project published at IEEE GLOBECOM 2019. Its official goal, as recorded in the original paper, is to analyze network performance. However, the same mechanism can be used for LTE reconnaissance against subscriber privacy.

See also: New Rayhunter tool helps detect Stingray attacks

How LTE reconnaissance works in local networks

FALCON runs on DragonOS, a Lubuntu-based Linux distribution with radio communication tools pre-installed. The attacker connects a LimeSDR or Ettus USRP B210 to USB 3.0, detects the frequency and Cell ID of the nearby tower, and begins decoding the Physical Downlink Control Channel (PDCCH). This channel carries the commands that direct each device when to receive and when to send data.

LTE reconnaissance is based on one essential feature: the PDCCH is not encrypted for network performance reasons. The Downlink Control Information (DCI) commands contain the Radio Network Temporary Identifiers (RNTIs) of each active device, the resources assigned to it, and the modulation rate. The FALCON receiver collects all this data in real time, without ever connecting to the network. The radio frequency itself carries all the information.

Cell phone tower with PDCCH LTE reconnaissance radio signals

What information is disclosed?

After activating the UE Activity tab in FALCON, the user sees the list of devices communicating with the tower. For each device, the RNTI, the transmission rate, the MCS index and the resource blocks per subframe are displayed. At the same time, an activity histogram is displayed showing which RNTIs consume the largest share of the network. This image is sufficient for mapping the devices in a specific geographical area.

The critical point here is that RNTIs are temporary identifiers, not permanent ones like IMSI or IMEI. A cell phone can change its RNTI several times a day. But that doesn’t eliminate the risk. An attacker with persistent monitoring at a specific location can correlate traffic patterns with other data sources and indirectly track individual users. At the same time, knowing the total load on the tower makes it possible to calculate how much traffic is needed to saturate the tower, opening the way for targeted denial-of-service attacks.

Related: Android: Users can disable 2G to block Stingray attacks

How dangerous is the technique really?

FALCON’s academic origins should not create complacency. The same principle—passive reading of control channels—is the foundation of IMSI-catcher devices (known as Stingrays) used by government agencies. The difference is the cost: instead of equipment worth tens of thousands of euros, a LimeSDR costs about $300. LTE reconnaissance with open source tools democratizes a capability that was previously exclusive to national services.

LimeSDR software defined radio connected to a laptop for LTE reconnaissance

The rapid increase in attacks on telecommunications providers adds to the concern. The Salt Typhoon, attributed to Chinese APT groups, breached at least nine US carriers in 2024—Verizon, AT&T, T-Mobile, and others—and gained access to CALEA systems, allowing them to see who was being monitored by US authorities. The US Treasury Department imposed sanctions on Sichuan Juxinhe Network Technology in January 2025 for organizing the operation. LTE reconnaissance is another link in the chain, allowing passive surveillance at the last step of the network, where the end-user device is connected.

How is the average user protected?

The defensive options for the everyday user are limited but do exist. The first step is to disable 2G support on your Android device —available as a setting from version 12 onwards— as older GSM technologies are easier targets for downgrade attacks that lead to IMSI-catchers. Second, using encrypted communication apps (Signal, iMessage, WhatsApp with end-to-end encryption) eliminates the value of intercepting traffic, even if the transmitted radio frequency is recorded. Third, updating the mobile operating system ensures that fixes for known vulnerabilities in the baseband processor have been applied.

Tools such as Rayhunter published by the EFF provide the ability to detect suspicious IMSI-catcher activity around the user. The SecNews technical team notes that protection against LTE reconnaissance at the network background level remains the responsibility of telecommunications providers themselves, who must develop 5G Standalone architectures with enhanced identifier protection (5G-GUTI, SUCI) that make it difficult to associate devices with permanent identities.

Read also: Impersonation attacks: 4G LTE networks exposed to hackers

The publication of the technique by communities like Hackers-Arise informs the cybersecurity community of a reality of interest to researchers and citizens alike: mobile spectrum is no longer the preserve of a closed circle. The key lesson is that privacy should never rely on the security of the underlying network — it must be ensured by users themselves through encrypted apps and updated devices.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS