Skip to content

rayhunter

EFF's IMSI-catcher detector — the installer for a supported hotspot, and the offline capture analyser

What it does

Two host-side tools from the EFF's Rayhunter project. rayhunter-installer puts the Rayhunter daemon onto a supported mobile hotspot over USB -- the Orbic RC400L or a TP-Link M7350/M7310 -- where it watches the cellular control traffic that device already sees and flags patterns characteristic of an IMSI catcher (a cell-site simulator). rayhunter-check analyses the QMDL captures such a device records, offline, on this machine.

Why you would want it

It is the only maintained, open, cheap way to detect cell-site simulators in the field, and the analyser lets you review captures after the fact. It is a detector: it transmits nothing and collects nothing of anyone else's, which is why it sits in rf-security rather than behind the rf-research consent gate.

Before it will work

A supported hotspot, its admin password, and a USB cable; the installer speaks USB directly (no adb needed) and today wants either root or a udev rule for the hotspot's identifiers -- the hardware-catalog entry that would supply the rule is the open item on issue #69. Running Rayhunter on this machine's own cellular modem is not possible with upstream as shipped; the same issue records why and the route.

How it installs

  • prebuilt zip from https://github.com/EFForg/rayhunter/releases/download/v0.12.0/rayhunter-v0.12.0-linux-x64.zip — arch x86_64
  • binaries, this block only:
    • installer → rayhunter-installer
    • rayhunter-check-linux-x64/rayhunter-check
  • prebuilt zip from https://github.com/EFForg/rayhunter/releases/download/v0.12.0/rayhunter-v0.12.0-linux-aarch64.zip — arch aarch64
  • binaries, this block only:
    • installer → rayhunter-installer
    • rayhunter-check-linux-aarch64/rayhunter-check
  • prebuilt zip from https://github.com/EFForg/rayhunter/releases/download/v0.12.0/rayhunter-v0.12.0-linux-armv7.zip — arch armv7l
  • binaries, this block only:
    • installer → rayhunter-installer
    • rayhunter-check-linux-armv7/rayhunter-check

Known problems

Upstream supports a short list of hotspots on purpose and asks for new hardware to go through its GitHub discussions, not issues. The daemon is not run here; nothing in this unit listens or captures on its own.

Keeping it current

  • probe: github release (EFForg/rayhunter)
  • strategy: reinstall
  • Tagged releases, each zip with a .sha256 beside it. A release is a new digest; re-pin from upstream's published file, never from a download alone.

Where to get help with the software itself

GitHub issues for bugs, GitHub discussions for new hardware.

Source: catalog/packages/rayhunter.yaml