AIMSICD: an Android app that watches for IMSI-Catchers and silent SMS
AIMSICD • Fight IMSI-Catcher, StingRay and silent SMS!
At a glance
- What is it?
- AIMSICD is an alpha-stage Android application that tries to spot fake base stations by comparing cell tower data on the device. It is a research tool with a long release gap, not a finished consumer product, and its own README says a lighter rewrite is in progress.
- Who is it for?
- AIMSICD is for Android users who understand it is an alpha research tool and want to inspect the detection logic themselves; it is not for anyone expecting a finished, support-backed product. Before installing, verify that the APK you download matches the GitHub or F-Droid listing, check which Android version the build targets, and read the open issues about detection methods, since the README itself points to those issue threads rather than a finished feature list.
- Can I use it commercially?
- Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
- Is it still maintained?
- Yes. The repository last received commits 25 days ago.
- What is it written in?
- Mainly Java, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What AIMSICD is trying to detect, and who it is for
An IMSI-Catcher is a fake mobile tower that sits between a phone and the real network, which the README describes as a Man-In-The-Middle attack. The same class of device is also called StingRay or cellular interception. AIMSICD is an Android app that tries to notice when that is happening. The README lists the detection methods it works on: tower information consistency, LAC and Cell ID consistency, neighboring cell info, prevention of silent app installations, signal strength monitoring, silent SMS detection, and FemtoCell detection. Each of those links to a GitHub issue rather than a finished, documented feature, which tells you where the project actually is. The audience is narrow. This is for someone who already knows what an IMSI-Catcher is, is willing to read issue threads to understand what a given detection does, and accepts an alpha build. The README's own framing is defensive rather than commercial: it argues that IMSI-Catchers are used at protests, that they can intercept calls and messages, and that identity thieves can build rogue GSM base stations from freely available tools. That is the case for the app existing, not a description of a polished product.
How the detection actually works on the device
AIMSICD does not need special radio hardware. It works from the cell information Android already exposes to applications, which is why the detection list reads like a set of consistency checks. Tower information consistency means comparing what the network claims about a tower against what the app expects. LAC and Cell ID consistency means watching the location area code and cell identifier for changes that do not match normal handover behavior. Neighboring cell info means looking at the cells the phone can see around it, because a fake tower often shows up as an unexpected neighbor. Signal strength monitoring is a supporting signal: an IMSI-Catcher is usually close to the target, so the pattern of signal changes can look different from a real tower. Silent SMS detection targets messages that arrive without a visible notification, which the wiki glossary defines as silent SMS. FemtoCell detection targets small consumer cells. The README does not publish thresholds, scoring, or false-positive rates for any of these, and the underlying logic lives in the linked issue threads and the AIMSICD/ source directory. Treat every detection as a heuristic that needs its own reading before you trust its output.
Installing AIMSICD on Android and running a first check
The README does not put the app on Google Play, and links to a wiki FAQ entry explaining why. It points to three distribution routes: the GitHub releases page, F-Droid, and an Aptoide store listing. The README gives no command-line install steps, and the repository files do not document a build command, so the practical path is to install the APK from one of those sources on the device. The repository layout is a Gradle project with a gradlew wrapper at the top level and the app module in AIMSICD/. It also contains keystore.jks.enc, which means release signing material is stored encrypted and is not usable without the key. After installing, the app needs the permissions its detection methods imply, and the README does not enumerate them, so check the permission prompt on first launch and decide whether each one is justified for what you want to run. A first real use is to open the app in a location where you know the local towers, leave it running, and watch whether any of the consistency checks fire. Because the checks are heuristics, a single alert is a prompt to look closer, not proof of an IMSI-Catcher. The README's warnings section is the place to read before drawing conclusions.
The release gap and what the README says about a revival
The most recent release listed is v0.1.43-alpha from 2016-05-01, and the two before it are v0.1.42-alpha and v0.1.41-alpha, both also from 2016. The README states plainly that the project will have a revival soon and that the team is working on a light version of AIMSICD, pointing to issue 926 for more information. The repository is not archived and the last push was on 2026-09-04, so there is current activity on the development branch even though no release has shipped in years. That combination matters when you decide to adopt it: you are running an alpha build from 2016, on a codebase that is still being touched, with a stated plan to replace it with something lighter. The development status badge in the README reads ALPHA. If you need a tool with a stable release cadence and a documented support story, this is the wrong project right now, and the README is the first place that says so.
Where AIMSICD stops being the right tool
AIMSICD is a phone-side detector built on data Android already provides. It cannot see the radio layer the way dedicated hardware can, and the README does not claim otherwise. If you need to identify a transmitter, locate it, or capture its signaling, a phone app is the wrong instrument. The same applies if you need a defensible measurement: the README does not document thresholds, calibration, or error rates, so an AIMSICD alert is not evidence you can hand to anyone. There is also a coverage limit implied by the detection list. Several checks depend on the network behaving in a way the app can compare against, and a network that is genuinely unusual, or a phone on a carrier whose cell data is sparse, can produce noise. The README's warnings section exists for a reason. Finally, the app is Android-only and Java-based, so iOS users and anyone who wants a cross-platform tool are outside its scope entirely.
How AIMSICD differs from hardware IMSI-Catcher detectors
The alternative approach is dedicated radio hardware, and the related searches around this project name several of them: BladeRF-based setups, portable IMSI catchers, and SigintOS. The difference is where the detection happens. AIMSICD reads the cell information Android exposes and looks for inconsistencies in it. A BladeRF or similar software-defined radio receives the actual signal, which means it can see things the phone's API never surfaces, but it also means you are carrying a radio, a host machine, and a power supply, and you need to understand the radio stack to interpret what you capture. SigintOS is a Linux distribution built for that kind of work. Neither approach is a strict upgrade over the other. A phone app runs everywhere you carry your phone and costs nothing extra; a radio setup gives you raw signal but not the convenience. If your question is whether the tower near you is fake and you want an answer while walking around, the phone-side approach is the one that fits. If your question is what the transmitter is doing, the phone app cannot answer it.
Licence, maintenance cost and what upgrading involves
AIMSICD is licensed under GPL-3.0. That matters if you plan to modify and redistribute it: the licence carries copyleft obligations, and the repository ships keystore.jks.enc rather than plain signing material, so a fork needs its own signing key. This is a description of the licence file, not legal advice; read the LICENSE text and, if you are distributing, get proper advice. The maintenance cost is the harder question. There has been no tagged release since 2016, the README announces a planned light version, and the detection methods are tracked as open issues rather than documented features. Upgrading means either tracking the development branch and building it yourself, or waiting for the revival the README describes. Neither gives you a version number to pin against. If you build from source, expect to keep a working Android SDK and Gradle setup around, because the repository is a standard Gradle project with a gradlew wrapper at the top level. If you install a prebuilt APK, you are depending on whoever published that artifact. Verify the source before you install it, since the README routes users to GitHub releases, F-Droid and Aptoide rather than a single first-party store.
Editorial conclusion
AIMSICD is for Android users who understand it is an alpha research tool and want to inspect the detection logic themselves; it is not for anyone expecting a finished, support-backed product. Before installing, verify that the APK you download matches the GitHub or F-Droid listing, check which Android version the build targets, and read the open issues about detection methods, since the README itself points to those issue threads rather than a finished feature list.
Frequently asked questions
How does AIMSICD detect an IMSI-Catcher?
It runs a set of checks on cell data Android already exposes, including tower information consistency, LAC and Cell ID consistency, neighboring cell info, signal strength monitoring, silent SMS detection and FemtoCell detection. The README links each method to a GitHub issue rather than a finished specification.
Can AIMSICD tell me if my Android phone is being monitored?
It attempts to flag conditions associated with IMSI-Catchers, such as inconsistent tower data and silent SMS, but the README does not document detection thresholds or error rates. An alert is a prompt to look closer, not proof that your phone is being monitored.
Does AIMSICD run on Android only?
Yes. It is an Android application written in Java, and the repository is a Gradle project with the app module in the AIMSICD/ directory. The README gives no other platform.
Is AIMSICD available on Google Play?
No. The README links to a wiki FAQ entry explaining why the app is not uploaded to Google Play, and instead points to GitHub releases, F-Droid and an Aptoide store listing.
What licence does AIMSICD use?
The repository is licensed under GPL-3.0, and the LICENSE file is at the top level. The repository also contains keystore.jks.enc, so release signing material is stored encrypted rather than in plain form.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/cellularprivacy-android-imsi-catcher-detector)