GSM Active
Such systems simulate a GSM base station to attract GSM phones away from the regular GSM network and to log them into the system’s virtual base station instead. As soon as the phone is logged onto the active system, its identity is extracted (IMSI and IMEI ). By logging the phone onto the virtual base station, it can be forced to transmit on a given channel, frequency, and time-slot (establishing a “silent call”). This transmission can be picked up by a direction finding system (vehicle based or handheld) which then reveals the exact position of the target phone.
When the target phone is logged into the active system, only calls that are initiated by the target can be placed, and no calls can be received by the target phone. In addition, phones can be completely taken off the real network (“intelligent jamming”), forged calls and SMS can be sent to the target phone, and private networking can be initiated by using the virtual base station. Furthermore, it is possible to drain the target phone’s battery, etc.
The active system also allows operation within UMTS networks. The target phone’s identity (IMSI, IMEI) can be retrieved without jamming the UMTS signal. For all other operations, such as locating the phone, intercepting, etc., the target UMTS phone will be pushed back into GSM mode by the system due to the two way authentication methods within UMTS networks.