Rayhunter: Detecting Cell-Site Simulators Across Europe
Discover Rayhunter, EFF's innovative tool for detection of IMSI catchers and malicious cell sites throughout the EU. Protect your privacy.
Rayhunteris an innovative open-source tool designed by theElectronic Frontier Foundation (EFF)to uncover and combat the use of cell-site simulators (CSS), commonly known asIMSI catchers or Stingrays. These covert surveillance devices are frequently used by law enforcement and other entities to track mobile phones without user knowledge.Rayhunteroffers an accessible and affordable way todetectsuspicious cellular activity, making it an essential resource for journalists, activists, and privacy-conscious citizens in Europe and beyond.
How Rayhunter Works
Rayhunter operates by continuously monitoring cellular network interactions for signs of interference. Specifically, the tool runs on an affordableOrbic mobile hotspot, available for less than £20, turning it into a portable surveillance detection unit. It tracks irregular behaviours from mobile base stations, such as attempts to downgrade a phone’s connection to vulnerable 2G networks or suspicious IMSI requests, both common indicators of IMSI catcher usage.
Simplicity and Accessibility
Rayhunter’s installation process is straightforward, requiring minimal technical expertise. Users simply download the latest software release, unzip the files, connect the Orbic hotspot to their computer, and execute a straightforward installation script compatible with Mac and Linux. Once operational, Rayhunter provides clear, immediate visual feedback via a simple user interface: a green (or blue for colourblind mode) indicator for normal operation and a red indicator for detected threats.
How Rayhunter Addresses EU Surveillance Concerns
While initially developed with a strong focus on surveillance within the United States, Rayhunter’s ease of use and affordability makes it particularly suited for deployment across Europe, where surveillance practices can often be less transparent. In countries lacking robust free speech protections, understanding the use and prevalence of CSS becomes even more crucial. Activists, journalists, and privacy advocates in the UK and across Europe can significantly benefit from using Rayhunter, identifying and mapping CSS usage to enhance digital privacy and civil liberties.
Technical Depth: What Rayhunter Detects
Rayhunter specifically monitors for:
- Connection Downgrade Attempts: Detecting unusual base station requests to revert connections to the insecure 2G network.
- Suspicious IMSI Requests: Identifying abnormal requests from base stations attempting to harvest unique identifiers without legitimate cause.
The data collected can be anonymously shared with the broader security community, enabling researchers to better understand, document, and develop defences against CSS threats.
Use Case: Activism and Journalism
Rayhunter’s simplicity and accessibility make it an invaluable tool for activists, journalists, and researchers. Its discreet operation allows users to detect surveillance without raising suspicion, offering real-time alerts that enable swift responses to potential threats. Additionally, the logs generated by Rayhunter can contribute significantly to research on the global prevalence and technical capabilities of IMSI catchers.
Joining the Surveillance Resistance
Rayhunter presents a compelling opportunity for communities across the UK and Europe to reclaim control over personal privacy and resist covert surveillance. By adopting Rayhunter, individuals and organisations can not only protect themselves from unlawful monitoring but also actively contribute to global awareness and improved cybersecurity measures.
Take Action
Interested in defending your digital privacy and supporting surveillance research?
- Get Rayhunter: Purchase an affordable Orbic hotspot, download Rayhunter, and begin detecting IMSI catchers today.
- Contact Cyber Defence: For professional advice on surveillance countermeasures or to explore managed security solutions, contact Cyber Defence today.
- Stay Informed: Explore related articles on Street-Level Surveillance and Digital Privacy Measures
- .
Together, we can uncover surveillance and protect our digital rights.





Stay Informed. Stay Secure.


Written by
Founder & Chief Executive
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
The FCC Foreign Router Ban: Supply Chain Risk, State-Sponsored Threat Actors, and What UK Enterprise Security Teams Must Do Now
The FCC's ban on foreign-made routers has direct implications for UK and EU enterprise security posture. We examine the threat model, regulatory context, and strategic response.
What Should a Board Expect from a Modern SOC Provider?
Cyber security has moved from the server room to the boardroom. Regulators, insurers, and shareholders now expect boards to demonstrate active oversight of cyber risk — and for most organisations, that means understanding what their Security Operations Centre provider is actually delivering. This article sets out the ten areas every board should scrutinise when evaluating a modern SOC provider, from detection engineering and threat intelligence to transparent reporting, compliance alignment, and measurable outcomes.
LockBit 5.0: New Version Targets Windows, Linux, and ESXi Systems
An in-depth analysis of LockBit 5.0, the:w! latest evolution of the prolific ransomware family, now targeting Windows, Linux, and VMware ESXi environments with enhanced evasion, cross-platform payloads, and refined extortion tactics.