Seeker: Geolocation via Social Engineering for Security Research
Accurately Locate Smartphones using Social Engineering
At a glance
- What is it?
- Seeker is a Python tool that demonstrates how a malicious website can request a browser's GPS-based location permission and collect device information without user grants. The author describes it as a proof of concept for educational purposes.
- Who is it for?
- Seeker is relevant for security researchers and penetration testers who need to demonstrate what data a fake webpage can collect from a phone that grants the location permission. The README states explicitly that it is a proof of concept for educational purposes only.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 103 days ago.
- What is it written in?
- Mainly CSS, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 27, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Seeker Demonstrates and Who Uses It
Seeker's stated purpose is to show what data a malicious website can gather from a visitor who grants a browser location permission. The README frames this as education: understanding the risk makes users less likely to grant critical permissions to unknown sites.
The tool works differently from IP geolocation. IP geolocation returns the approximate location of an ISP, which is often hundreds of kilometers from the actual user. Seeker uses the browser's HTML Geolocation API to request GPS coordinates directly from the device's hardware. The README states that when a user accepts location permission, accuracy is typically within approximately 30 meters on a smartphone with a working GPS.
The primary users are penetration testers conducting authorized social engineering assessments and security researchers demonstrating browser permission risks.
Seeker also collects significant device information without requiring any permission from the browser. This passive collection happens in the background from any visitor to the fake page, regardless of whether they accept or deny the location prompt. The README documents these passive data points explicitly: canvas fingerprinting, operating system, browser, IP addresses, screen resolution, approximate RAM, and GPU information. This part of the demonstration is particularly relevant for privacy discussions because it shows what any website can learn about a visitor without any interaction.
Installing Seeker
For Kali Linux, Arch Linux, Ubuntu, Fedora, Parrot OS, and Termux:
git clone https://github.com/thewhiteh4t/seeker.git
cd seeker/
chmod +x install.sh
./install.shFor BlackArch Linux, Seeker is available in the package manager:
sudo pacman -S seekerDocker is another option:
docker pull thewhiteh4t/seekerOn macOS, clone the repository and run the Python file directly:
git clone https://github.com/thewhiteh4t/seeker.git
cd seeker/
python3 seeker.pyThe Dockerfile is based on Alpine Linux and installs Python, PHP, pip, and psutil. It exposes port 8080.
How Seeker Works: Fake Templates and Data Collection
Seeker hosts a local web server (default port 8080) that serves a fake page chosen from a set of built-in templates. When a visitor opens the page and grants the location permission prompt, the browser sends GPS coordinates back to the Seeker server.
Beyond location, Seeker collects device information without requiring any permission. The README lists: a unique device ID via canvas fingerprinting, device model (not always available), operating system, platform, approximate CPU core count, approximate RAM amount, screen resolution, GPU information, browser name and version, public IP address, local IP address, and local port.
After receiving this data, Seeker performs automatic IP address reconnaissance on the collected public IP.
Available templates include NearYou, Google Drive, WhatsApp, Telegram, Zoom, and Google reCAPTCHA. The README documents how to create custom templates and contribute them via pull request.
Usage is started with:
python3 seeker.py -hThe `-t` flag selects a template by index, `-p` sets the port, and `--telegram` or `--webhook` send results to an external endpoint.
Tunneling: Reaching Devices Outside the Local Network
Seeker runs a local server. For the fake page to be reachable from a remote device, the server must be exposed through a tunnel. The README gives two options.
The first uses the free `localhost.run` service via SSH:
ssh -R 80:localhost:8080 [email protected]The second uses ngrok. On macOS:
brew install ngrok/ngrok/ngrok
ngrok http 8080Both approaches create a public URL that forwards to the local Seeker instance. The resulting link or QR code is what the tester sends to the target as the social engineering payload.
Limitations and Accuracy Constraints
GPS accuracy varies by device and environment. The README documents several factors that reduce accuracy: laptops typically have no GPS hardware and fall back to IP geolocation or cached coordinates; some browsers block JavaScript or location APIs; and uncalibrated GPS on a phone produces inaccurate results.
The altitude, direction, and speed fields are conditional. Altitude is not always available. Direction and speed are only populated when the user is moving at the time of the request.
Seeker requires that the target visit the page voluntarily and grant the location permission. A user who dismisses the permission prompt provides no coordinates. Modern mobile browsers have tightened location permission flows, and users increasingly recognize the pattern. The tool depends on social engineering success, not a technical bypass of browser security.
Comparing Seeker to IP Geolocation
IP geolocation tools map an IP address to a geographic region using a database of ISP assignments. The result is typically the city where the ISP has a network presence, not the user's physical location. This is the method many web analytics tools use by default.
Seeker is the contrasting approach: it does not use the IP address for location at all. It uses the browser's hardware-level GPS API. The difference in precision, when the user grants permission, is the gap between city-level accuracy and 30-meter accuracy.
The trade-off is that Seeker requires user interaction (the permission grant) while IP geolocation is passive. For red team exercises that need to demonstrate the difference between the two methods, Seeker provides the concrete evidence.
Seeker also performs automatic IP reconnaissance on the public IP it collects. This means even visitors who deny the location permission expose their public IP, which Seeker then processes for network information. The combination of passive device fingerprinting and active IP reconnaissance in one tool is what makes it a useful demonstration platform for security awareness training.
The README notes that Seeker has been tested on a wide range of platforms: Kali Linux, BlackArch Linux, Ubuntu, Fedora, Kali Nethunter, Termux, Parrot OS, and macOS Monterey. The breadth of supported platforms reflects that the tool is designed to run on whatever system a security researcher has available.
Editorial conclusion
Seeker is relevant for security researchers and penetration testers who need to demonstrate what data a fake webpage can collect from a phone that grants the location permission. The README states explicitly that it is a proof of concept for educational purposes only. Outside of a controlled security assessment with proper authorization, using Seeker against a third party is outside its stated scope. The MIT license applies to the code, but authorization from the target's owner is the operator's responsibility. The last push was on 2026-06-19.
Frequently asked questions
How do I install Seeker on Termux?
Clone the repository with git clone https://github.com/thewhiteh4t/seeker.git, then run chmod +x install.sh and ./install.sh inside the cloned directory. The README lists Termux as a tested environment alongside Kali, BlackArch, Ubuntu, Fedora, and Parrot OS.
What device information does Seeker collect without permissions?
According to the README, Seeker collects a unique ID via canvas fingerprinting, operating system, platform, approximate CPU core count, approximate RAM, screen resolution, GPU information, browser name and version, public IP, local IP, and local port. These are gathered without requesting any browser permission.
Does Seeker work on laptops?
The README states that Seeker works best with smartphones. On a laptop without GPS hardware, it falls back to IP geolocation or cached coordinates rather than precise GPS coordinates. Accuracy in the fallback mode is much lower than the approximately 30 meters possible on a phone with a working GPS.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/thewhiteh4t-seeker)