SNI5GECT: A Practical Approach to Inject aNRchy into 5G NR
Shijie Luo
34th USENIX Security Symposium (USENIX Security '25) · Day 3 · Network Security 3: BLE and Cellular
Overview
The talk "SNI5GECT: A Practical Approach to Inject aNRchy into 5G NR" introduces a novel framework designed to passively sniff and actively inject messages into 5G New Radio (NR) communications. Presented by Shijie Luo at USENIX Security, this research challenges conventional assumptions about 5G security by demonstrating practical attacks against the unencrypted portions of the 5G initial access procedure. Unlike traditional rogue base station attacks, SNI5GECT operates covertly, making it difficult to detect while enabling potent exploits against user equipment (UE).

Key moments
- 0:00 Introduction to SniffJet and 5G threat model
- 1:29 Overview of the SniffJet framework
- 2:51 Detailed design of SniffJet's core components
- 5:08 SniffJet's three categories of supported attacks
- 6:00 One-shot attack example: Crashing UE modem
- 7:05 Multi-stage attack example: Authentication replay
- 7:47 SniffJet's sniffing and injection performance evaluation
SNI5GECT: A Practical Approach to Inject aNRchy into 5G NR
Speakers: Shijie Luo, as presented
Conference: USENIX Security
YouTube: https://www.youtube.com/watch?v=-p3f7KL4acI
Overview
The talk "SNI5GECT: A Practical Approach to Inject aNRchy into 5G NR" introduces a novel framework designed to passively sniff and actively inject messages into 5G New Radio (NR) communications. Presented by Shijie Luo at USENIX Security, this research challenges conventional assumptions about 5G security by demonstrating practical attacks against the unencrypted portions of the 5G initial access procedure. Unlike traditional rogue base station attacks, SNI5GECT operates covertly, making it difficult to detect while enabling potent exploits against user equipment (UE).
The significance of SNI5GECT lies in its ability to exploit vulnerabilities at the physical layer and during the initial communication phases before cryptographic keys are established. This period, where signals and messages remain unencrypted, presents a critical attack surface that SNI5GECT leverages with precision timing and frequency synchronization. The framework's capability to execute attacks such as modem crashes, forced downgrades to older generations, authentication bypasses, and device fingerprinting highlights a fundamental weakness in current 5G security paradigms.
This work matters deeply to the security community because it provides the first practical toolset for passive sniffing and active spoofing of 5G NR signals over the air without requiring a full rogue base station. By demonstrating these capabilities, SNI5GECT not only exposes critical vulnerabilities but also offers researchers a powerful platform to further analyze 5G security, perform realistic penetration testing, and develop robust countermeasures against sophisticated, undetectable attacks in next-generation cellular networks.
Background
▶ Watch: Introduction to SniffJet and 5G threat model (0:00)
The security landscape of 5G cellular networks has traditionally focused on protecting the core network and encrypted communication channels. However, the initial access phase, where a User Equipment (UE) first connects to a base station (gNB), remains a significant area of concern. During this phase, critical control plane messages and physical layer signals are transmitted unencrypted, creating an inherent window of vulnerability. Prior research and common threat models for cellular networks often assume a man-in-the-middle (MiTM) attacker operating a rogue base station. While effective, rogue base stations are typically easily detectable because they must broadcast strong "responder" signals to attract UEs, making them conspicuous. Furthermore, there has been a notable lack of practical tools specifically designed for passive sniffing and targeted spoofing of 5G NR signals over the air between a legitimate base station and a UE.
The problem SNI5GECT addresses stems from this gap. Existing tools often require privileged access to network infrastructure or rely on the visible operation of a rogue base station. This limitation hinders realistic security assessments and the development of countermeasures against more subtle, stealthy attacks. The unencrypted nature of initial 5G NR communication — encompassing signals like the Synchronization Signal Block (SSB) and messages such as Radio Resource Control (RRC) Setup and Registration Request — provides an attacker with a prime opportunity. Without encryption, a malicious entity can intercept, analyze, and potentially manipulate these exchanges, influencing the UE's behavior without needing to fully impersonate a base station.
The challenge in exploiting this vulnerability lies in the precision required for 5G NR. The system relies on highly synchronized time and frequency domains, making it difficult for an attacker to accurately inject messages that a UE will accept as legitimate. Any injected signal must align perfectly with the timing and frequency of the legitimate base station to be processed by the UE, which cannot distinguish between a legitimate and an injected message if the physical layer characteristics are identical. SNI5GECT’s innovative approach, particularly its use of the overshadow technique, directly tackles this challenge, enabling covert and effective manipulation of 5G NR communications by precisely mimicking the legitimate base station's transmission parameters.
Key Findings
▶ Watch: Detailed design of SniffJet's core components (2:51)
The central discovery of the SNI5GECT research is the practical demonstration of a framework capable of performing both passive sniffing and active injection of messages into 5G NR communications without operating a full-fledged rogue base station. This capability fundamentally alters the perceived threat model for 5G initial access, proving that sophisticated, undetectable attacks are feasible at the physical and control plane layers before security context establishment.
Key findings include:
- Novel Attacker Model and Implementation: SNI5GECT introduces and validates an attacker model where a passive or active attacker, operating within radio range, can eavesdrop on unencrypted downlink and uplink messages and inject or replay messages without needing subscriber credentials, cryptographic keys, or privileged access to the network. This bypasses the detectability issues associated with rogue base stations.
- Precise Synchronization and Overshadow Technique: The framework's ability to achieve precise time and frequency synchronization with a target base station by decoding the Synchronization Signal Block (SSB) is a critical enabler. This allows SNI5GECT to use the overshadow technique, transmitting injected messages at the exact same frequency and time as the legitimate base station, making them indistinguishable to the UE.
- Comprehensive Sniffing Capabilities: SNI5GECT demonstrated robust sniffing performance, achieving approximately a 90% success rate in downlink (DL) sniffing and a 70% success rate in uplink (UL) sniffing. These rates were maintained across distances up to 20 meters, with UL sniffing showing robustness to Timing Advance (TA) variations of up to ±4 (corresponding to ±1 microsecond).
- Effective Injection Capabilities: The injection mechanism proved highly effective, with success rates increasing with the number of message duplications. With a 30dB amplifier, SNI5GECT achieved up to an 80% injection success rate at distances up to 20 meters. Even without an amplifier, real-world attacks on commercial 5G devices achieved up to a 40% success rate.
- Diverse Attack Categories: The research successfully demonstrated three categories of attacks:
- One-shot attacks: Triggering immediate reactions like modem crashes or forced downgrades.
- One-shot attacks with response: Enabling device fingerprinting by eliciting specific responses.
- Multi-stage attacks: Executing complex exploits such as authentication replay by combining sniffing and injection across multiple communication states.
- Reusable Research Tool: Beyond specific attacks, SNI5GECT is presented as a highly reusable framework for 5G security research. It enables realistic testing without rogue base stations, facilitates throughput analysis, detailed traffic analysis for privacy research, and provides valuable packet capture (PCAP) datasets for anomaly detection studies.
These findings collectively underscore a significant vulnerability in the foundational layers of 5G NR and provide a potent tool for both offensive security research and defensive development.
Technical Deep Dive
▶ Watch: SniffJet's three categories of supported attacks (5:08)
SNI5GECT, short for "sniff + 5G + inject," is an elaborate framework designed to interact with 5G NR communications at a granular level. Its power lies in its ability to precisely synchronize with a legitimate 5G base station (gNB) and a target User Equipment (UE), allowing for both passive monitoring and active manipulation of unencrypted over-the-air messages.
Attacker Model:
The attacker model assumed by SNI5GECT is critical to understanding its capabilities and implications. The attacker is positioned within the radio range of both the target UE and the legitimate gNB. Crucially, this attacker does not possess privileged access to the base station or the core network, nor do they have access to the subscriber's credentials or cryptographic keys. Instead, the attacker's capabilities are limited to:
- Eavesdropping: Passively sniffing unencrypted messages, such as RRC Setup and Registration Request, which occur during the initial access phase.
- Injection/Replay: Actively injecting or replaying messages over the downlink communication channel towards the UE. The key enabler here is the overshadow technique, where the attacker transmits at the exact same frequency and time as the legitimate base station. Because the physical layer is unencrypted, the UE cannot distinguish between a legitimate and an attacker-injected message, accepting and reacting to the injected content.
Framework Components:
SNI5GECT is composed of three major, interconnected components: the Sinker, the Broadcast Worker, and the UE Tracker, which itself contains several sub-components for dynamic interaction.
- The Sinker:
- This is the foundational component responsible for establishing and maintaining synchronization with the target gNB.
- It operates by continuously searching for and decoding the Synchronization Signal Block (SSB). The SSB is a crucial broadcast signal in 5G NR that provides the UE with essential information for initial access, including physical cell ID, frame timing, and frequency synchronization.
- Once synchronized, the Sinker diligently tracks the SSB block to ensure synchronization is maintained, even if temporary signal loss occurs.
- Furthermore, it captures and forwards subframes to other SNI5GECT components for further decoding and processing, acting as the primary data acquisition layer.
- The Broadcast Worker:
- Building upon the Sinker's synchronization, the Broadcast Worker decodes System Broadcast Information from the gNB. This primarily includes SIB1 (System Information Block Type 1), which contains vital cell-specific information and basic configurations required for a UE to initiate a connection to the network.
- After applying these configurations, the Broadcast Worker shifts its focus to detecting Random Access Response (RAR) messages from the gNB. The RAR is the first message transmitted from the gNB to a UE after the UE initiates the Random Access (RA) procedure.
- Detecting and decoding RAR messages is critical because it signals the presence of a new UE attempting to connect to the target cell. When a new UE is detected, SNI5GECT dynamically activates a UE Tracker instance to monitor its subsequent interactions.
- The UE Tracker:
- This component is instantiated for each new UE detected and is responsible for monitoring its entire communication lifecycle with the gNB. It meticulously tracks the UE's communication state and its specific configurations as they evolve.
- The UE Tracker itself comprises several sub-components:
- UE DL Worker: This worker is dedicated to decoding all downlink messages (gNB to UE) that are specific to the tracked UE.
- gNB UL Worker: Conversely, this worker decodes all uplink messages (UE to gNB) originating from the tracked UE.
- Exploit Module: This is a highly flexible, user-defined script that represents the "brain" of the attack. Messages decoded by either the UE DL Worker or gNB UL Worker are passed to this module. The exploit module's role is to:
- Dissect the incoming message and analyze the current communication state.
- Determine if the current state is suitable for executing a predefined attack.
- If conditions are met, it generates a malicious response message tailored to the specific attack. For example, upon detecting a Registration Request from the UE, an exploit module might generate a Registration Reject message.
- gNB/UE Injector: This final sub-component takes the malicious message generated by the exploit module and prepares it for transmission. It encodes the message, generates the necessary scheduling information (e.g., for an uplink grant if the UE is expected to respond), and then injects these signals towards the target UE. To increase the likelihood of success, the injector often transmits the malicious message with a few duplications. As previously noted, due to the unencrypted physical layer, the UE accepts the message and reacts accordingly, believing it originated from the legitimate gNB.
Attack Categories:
SNI5GECT supports three primary categories of attacks, showcasing its versatility:
- One-Shot Attacks:
- These attacks involve a single injected message triggering an immediate and significant reaction from the UE.
- Example 1: Modem Crash: After sniffing an RRC Setup Request from the target UE, SNI5GECT injects a malformed RRC Setup message. Upon receiving this specially crafted message, the UE's modem crashes immediately, rendering the device unable to connect to the network.
- Example 2: Forced Downgrade: Following the sniffing of a Registration Request from the UE, SNI5GECT injects a spoofed Registration Reject message. When the UE receives this rejection, it ignores subsequent legitimate Security Mode Command messages from the gNB and instead initiates a downgrade to an earlier generation network, such as LTE.
- One-Shot Attacks with Expected Response (Fingerprinting):
- These attacks involve injecting a message that elicits a specific, useful response from the UE, often for information gathering.
- Example: Device Fingerprinting: When the attacker observes a Registration Request from the UE, SNI5GECT injects an Identity Request message along with an uplink grant. If the UE accepts this injected message, it will respond with an Identity Response, revealing potentially valuable information about the device that can be used for fingerprinting.
- Multi-Stage Attacks:
- These are more complex attacks that involve continuous sniffing and multiple injections across different communication states, often replaying previously captured messages.
- Example: Authentication Replay Attack: This attack targets the authentication process. After the UE sends a Registration Request, SNI5GECT replays a previously captured Authentication Request message. The UE responds with an Authentication Failure. SNI5GECT then updates the sequence number (a critical step to bypass replay detection mechanisms) and replays the Authentication Request again. This repeated failure eventually causes the UE's internal timer T3520 to expire. When this timer expires, the UE abandons the 5G connection attempt and downgrades to LTE, remaining in this degraded state for an extended period, potentially up to 300 seconds.
Evaluation and Performance:
The SNI5GECT framework was rigorously evaluated using srsRAN (Software Radio Systems RAN) as a legitimate base station.
- Sniffing Capability: Achieved approximately 90% success rate in downlink (DL) sniffing and 70% in uplink (UL) sniffing.
- Distance Performance: DL sniffing remained robust for distances up to 20 meters across different phones, with only a slight decrease in success rate. UL sniffing, which relies on Timing Advance (TA) commands, also proved robust for TA variations of up to ±4, corresponding to a time mismatch of ±1 microsecond.
- Injection Capability: Injection success rate increased with the number of message duplications. Using a 30dB amplifier, SNI5GECT achieved up to an 80% success rate at distances up to 20 meters. Without an amplifier, real-world attacks on four commercial 5G devices (using srsRAN and Open5GS as legitimate base stations) achieved up to a 40% success rate.
These technical details underscore the precision, modularity, and practical effectiveness of the SNI5GECT framework in manipulating 5G NR communications.
Demo / Proof of Concept
▶ Watch: Multi-stage attack example: Authentication replay (7:05)
The talk included compelling demonstrations of SNI5GECT's capabilities, showcasing two distinct attack types: a one-shot modem crash and a multi-stage authentication replay attack. These demonstrations provided concrete evidence of the framework's effectiveness against commercial 5G devices.
Demo 1: 5G UE Modem Crash
This demonstration illustrated a one-shot attack where a single injected malformed message caused an immediate crash of the target UE's 5G modem.
- Setup:
- On the left side of the screen, the legitimate 5G network was simulated using Open5GS (a 5G core network implementation) coupled with srsRAN (a software radio system acting as the gNB).
- An MC Catcher tool was used to monitor for any downgrades to 4G (LTE), indicating a disruption in 5G service.
- On the right, the screen of the target UE was projected, allowing the audience to observe its behavior directly.
- In the middle terminal, the SNI5GECT framework was running. A separate terminal displayed ADB monitor logs from the UE, which are crucial for detecting modem crashes.
- Execution:
- The attacker started SNI5GECT.
- The UE's airplane mode was turned off, triggering it to attempt to connect to the legitimate 5G base station (srsRAN).
- SNI5GECT, in its sniffing phase, detected the UE sending an RRC Setup Request message to the gNB.
- Immediately upon detecting this, SNI5GECT injected a malformed RRC Setup message towards the UE.
- The UE, unable to distinguish between the legitimate and injected messages due to the overshadow technique, processed the malformed message.
- The ADB monitor logs on the UE's side quickly displayed the message "CS modem reason is detected," which unequivocally indicated that the UE's 5G modem had crashed. The UE effectively lost its ability to connect to the 5G network. The legitimate RRC Setup from the base station was ignored.
Demo 2: Authentication Replay Attack
This demonstration showcased a more complex, multi-stage attack involving both sniffing and replaying messages to force a persistent downgrade to LTE.
- Setup:
- The same Open5GS + srsRAN setup was used for the legitimate 5G network.
- MC Catcher was again used to monitor for 4G connections.
- The target UE's screen was projected.
- SNI5GECT was running in a terminal.
- Execution (Sniffing Phase):
- First, SNI5GECT was loaded with a sniffer module specifically designed to capture Authentication Request messages.
- The UE's airplane mode was toggled (off then on) to trigger its connection attempt to the 5G base station.
- During this connection, SNI5GECT successfully sniffed a legitimate Authentication Request message sent from the gNB to the UE. This message was then copied and used to update SNI5GECT's authentication replay module.
- Execution (Injection/Replay Phase):
- SNI5GECT was restarted, loading the newly updated authentication replay module containing the captured Authentication Request.
- The UE's airplane mode was turned on again to initiate another connection attempt.
- As the UE approached the 5G base station, SNI5GECT began replaying the captured Authentication Request message.
- The UE responded with "authentication failure" several times. SNI5GECT, as part of its multi-stage logic, updated the sequence number of the replayed message to ensure it wasn't simply discarded as a duplicate.
- Eventually, after repeated authentication failures, the UE's internal timer T3520 expired. This caused the UE to release its connection to the 5G network.
- Crucially, on the MC Catcher side, it was observed that the UE then attempted to connect to a 4G (LTE) base station, completely ignoring the available 5G base station.
- Even after toggling the airplane mode again, the UE still connected to the 4G base station, demonstrating that the downgrade persisted. The talk mentioned this state can last for up to 300 seconds.
These demos effectively validated SNI5GECT's practical utility and the severe impact its attacks can have on 5G UEs.
Defensive Implications
▶ Watch: SniffJet's sniffing and injection performance evaluation (7:47)
The SNI5GECT research uncovers critical vulnerabilities in the initial access procedures of 5G NR, particularly concerning the handling of unencrypted messages and physical layer signals. The capabilities demonstrated by SNI5GECT necessitate a re-evaluation of current defensive strategies for 5G networks and user equipment. Defenders, including network operators, UE manufacturers, and security researchers, should consider the following implications and countermeasures:
- Enhanced UE Message Validation: The core of SNI5GECT's attacks relies on UEs accepting maliciously crafted or replayed unencrypted messages as legitimate. UE software and hardware should implement more robust validation mechanisms for all incoming messages, even those received before security context establishment. This could include:
- Strict format adherence: Rejecting any message that deviates from the 3GPP specifications, even if only subtly malformed (as seen in the RRC Setup crash).
- Contextual validation: Analyzing message sequences and rejecting messages that are out of order or do not align with the expected communication state, even in unencrypted phases.
- Entropy/randomness checks: While challenging for unencrypted data, detecting patterns in replayed messages beyond simple sequence numbers could be explored.
- Anomalous Behavior Detection at the gNB/Core Network: While SNI5GECT operates covertly from the UE's perspective, the gNB and core network may still observe anomalous behavior from affected UEs.
- Rapid connection/disconnection cycles: A UE repeatedly attempting to connect and then abruptly failing or crashing might indicate an attack.
- Sudden, persistent downgrades: If a UE capable of 5G consistently downgrades to LTE or older generations, especially after failed authentication attempts, this could be a red flag.
- Unusual authentication failures: A high rate of authentication failures or specific types of failure codes could signal replay attacks.
- Network monitoring systems should be enhanced to detect these patterns and potentially blacklist or quarantine affected UEs for further investigation.
- Physical Layer Hardening and Integrity Checks: The fact that UEs cannot distinguish between legitimate and injected signals at the physical layer highlights a fundamental challenge. While encryption protects data, the control plane's integrity during initial access is paramount.
- Explore lightweight, non-cryptographic integrity checks or authentication mechanisms for critical control plane messages even before full security setup. This is a complex area, as it would require modifications to 3GPP standards.
- Research into physical layer authentication techniques, where the unique radio fingerprint of a legitimate gNB could be used to verify transmissions, might offer a long-term solution.
- Improved Modem Resilience: UE manufacturers must focus on building more resilient modem firmware that can withstand malformed messages without crashing. A modem crash is a denial-of-service attack that can be easily triggered and significantly degrades user experience. Robust error handling and fault isolation within the modem's operating system are crucial.
- Standard Enhancements for Initial Access Security: The 3GPP standards body should investigate potential enhancements to the 5G NR initial access procedures. This could involve:
- Minimizing the window of unencrypted communication.
- Introducing early authentication or integrity protection for critical messages like RRC Setup and Registration Request.
- Re-evaluating the role and security implications of timers like T3520 in the context of replay attacks.
- Utilize SNI5GECT for Proactive Testing: The framework itself can be a powerful tool for defenders. Security teams can leverage SNI5GECT's sniffing and injection capabilities to:
- Proactively test the resilience of their UEs and network infrastructure against these specific attack vectors.
- Develop and validate intrusion detection systems (IDS) by generating realistic attack traffic.
- Analyze traffic patterns for privacy implications, as highlighted by the researchers.
By addressing these defensive implications, the 5G ecosystem can move towards a more robust and resilient security posture against sophisticated, over-the-air attacks like those demonstrated by SNI5GECT.
Key Takeaways
- Novel Attack Model: SNI5GECT demonstrates practical passive sniffing and active injection attacks against 5G NR without requiring a detectable rogue base station, challenging traditional cellular threat models.
- Overshadow Technique: The framework's precise time and frequency synchronization with legitimate gNBs enables the "overshadow technique," making injected messages indistinguishable to UEs at the physical layer.
- Diverse Attack Capabilities: SNI5GECT facilitates various attacks, including modem crashes, forced downgrades to LTE, device fingerprinting, and multi-stage authentication replay, exploiting unencrypted initial access procedures.
- High Success Rates: The framework achieved up to 90% success in DL sniffing, 70% in UL sniffing, and up to 80% injection success at 20 meters with an amplifier, proving its practical effectiveness against commercial devices.
- Critical Vulnerability Exposure: The research highlights a fundamental security gap in 5G NR, where unencrypted physical layer signals and control plane messages during initial access are vulnerable to undetectable manipulation.
- Valuable Research Tool: SNI5GECT serves as a powerful, reusable tool for 5G security research, enabling realistic testing, traffic analysis, and anomaly detection studies without complex rogue base station setups.
About the Speaker(s)
Shijie Luo presented the "SNI5GECT: A Practical Approach to Inject aNRchy into 5G NR" talk at the USENIX Security conference. While specific affiliations or titles were not provided in the talk metadata or transcript, Shijie Luo represented the research team responsible for developing this innovative framework. The presentation showcased deep expertise in 5G cellular network protocols, software-defined radio (SDR) implementations, and practical exploitation techniques against modern communication systems.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Solid, original work that actually advances the 5G attack surface conversation rather than just restating the known-bad rogue base station playbook. The overshadow technique combined with precise SSB synchronization is the real contribution here — it's a meaningful step toward stealthy, non-detectable cellular attacks that practitioners need to understand now, not after carriers finish their 5G buildouts.
Heather Calloway (CISO) — WEAK
Technically credible research that exposes a real and underappreciated attack surface in 5G initial access — but it stops at the lab bench. The defensive implications are a wishlist aimed at standards bodies and chip vendors, not a usable decision path for any operator, CISO, or policymaker in the room.
→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)
All talks from 34th USENIX Security Symposium (USENIX Security '25)