orbic-rc400l¶
Orbic RC400L (also Kajeet RC400L) — the mobile hotspot Rayhunter's IMSI-catcher detector runs on
Vendor: Orbic
Status: untested — catalogued from documented sources, not yet proven here.
Not maintainer-verified: nobody on this project has run this hardware yet. The two facts are recorded separately on purpose (D-027) — a correct recipe and a tested device are different claims.
What it is¶
A cheap Qualcomm-based 4G mobile hotspot that the EFF's Rayhunter project turns into an IMSI-catcher detector: its daemon runs on the hotspot and watches the cellular control traffic the device already sees. The RC400L is upstream's recommended device for the Americas.
What you can do with it¶
Detect cell-site simulators in the field, on a device that fits in a pocket, and review its captures later with rayhunter-check on this machine. Defensive only: it transmits nothing and collects nothing of anyone else's (docs/guides/rayhunter.md).
Setup¶
Install the rayhunter unit, connect the hotspot over USB, and run rayhunter-installer orbic --admin-password <the device's admin password>; the device reboots itself when the installer finishes. Until this entry's identifiers are confirmed and a product-string rule exists, the installer may need root to reach the device.
Known problems¶
The identifiers here are from upstream's source, not measured; the udev rule that would give the operator access without root waits on one lsusb from the maintainer's own unit. Upstream supports a short list of hotspots on purpose and takes new hardware through GitHub discussions.
How it identifies itself¶
| USB id | What | Confirmed | Node |
|---|---|---|---|
05c6:f601 |
Orbic RC400L in its normal composition, as the installer waits for it | no | libusb |
05c6:f626 |
The composition the installer opens on the device (open_usb_device(VENDOR_ID, 0xf626)) | no | libusb |
⚠ 05c6:f601 is not unique to this device (vendor_chip_default; also used by: other Qualcomm-based hotspots and USB modems in their default composition). 05c6 is Qualcomm, Inc. and f601 carries no product name in usb.ids; Qualcomm reference designs ship with the chip vendor's identifiers and several hotspots and modems present the same pair. Nothing but a product or serial string can tell the RC400L from them, and neither is measured.
⚠ 05c6:f626 is not unique to this device (vendor_chip_default; also used by: other Qualcomm-based devices presenting this composition). Qualcomm vendor id, no product name in usb.ids, no product string measured; see f601.
What is not yet known¶
The identifiers below come from upstream's installer source, not from this device on a bench: EFForg/rayhunter installer/src/orbic.rs (commit 15630ed9c7ac, 2026-09-10) waits for 05c6:f601 and opens 05c6:f626, and speaks to both directly over USB (nusb). Neither has a product string on record here, and 05c6 is Qualcomm's vendor id used by every Qualcomm-based reference design, so a rule on the bare pair over-matches other Qualcomm hotspots and modems. The maintainer owns a Rayhunter unit: one scripts/identify-device.sh run with it attached closes this with the product and serial strings, and the rule then matches on them (D-028). The TP-Link M7350/M7310 route is not USB-identified in the installer at all and gets no entry until one is measured.
Who can close it: the maintainer owns this hardware; the gap closes at the next capture session.
Access and permissions¶
Group membership required: plugdev — added at install, applies at next login.
Software that makes it useful¶
Upstream: https://github.com/EFForg/rayhunter