Resource / Blogs /

From GNSS Fundamentals to Static GPS Spoofing

How GPS spoofing works: GNSS basics, trilateration, GPS architecture and a static spoofing demo with HackRF One, plus practical mitigations.
By
Shubham Thorat
June 15, 2026
8 min
Get Tested
Device, firmware and APIs scoped as one system.
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.

Key Takeaways

  • GPS finds your position using signals from three satellites, with a fourth to keep timing accurate.
  • The GPS system has three parts: the space segment, the user segment and the control segment.
  • GPS signals are weak by the time they reach Earth, so they are easy to jam or fake.
  • Most civilian GPS receivers cannot check whether a signal comes from a real satellite.
  • With a HackRF One and gps-sdr-sim, an attacker can send fake signals that set a false location.
  • Spoofing can mislead cars, ships, aircraft, fleet trackers and IoT devices that rely on GPS.
  • Navigation Message Authentication, sensor checks and other location sources help detect spoofing.

Introduction to GPS

GNSS stands for Global Navigation Satellite System, which is a satellite-based navigation system that provides geolocation for users in real-world situations. Different groups/countries invented different navigation systems such as GPS, GLONASS, etc. GNSS generally cannot fail, but if one fails, GNSS receivers can pick up signals from other systems.

We are going to discuss GPS (Global Positioning System), which was invented by the US military. GPS consists of approximately 31 satellites which are orbiting at an altitude of 20,200km from earth. These orbits are arranged in such a way  that at least 6 satellites are always within line of sight from anywhere on earth’s surface. Each satellite sends the signal with data about the location of the device and at what time it is transmitting. GPS positioning works on the TRILATERATION process, which means three satellites are used to share the accurate location (Latitude, Longitude, Height) of the user and a fourth satellite is used to maintain the clock/timing accuracy.

Let’s understand the Trilateration process quickly:

  • Imagine each GPS satellite drawing an invisible sphere around itself, with you somewhere on its surface. A signal from one satellite alone can only tell you that you’re somewhere on that sphere, not exactly where.
  • When a second satellite adds its signal, the two spheres overlap. Now your position is narrowed down to the line where those two spheres intersect a much smaller area.
  • A third satellite joins in, and where all three spheres intersect is your exact position on Earth. This process is called trilateration using distances, not angles, to pinpoint a location.
  • Finally, a fourth satellite helps fine-tune your clock and timing accuracy, since even tiny timing errors can cause big mistakes in distance calculations.
Trilateration in GPS

Applications of GPS  in the Real World

GPS is one of those technologies we use every day without even thinking about it. It shows up in so many domains, but it becomes especially useful in IoT and the automotive industry. From basic location tracking to mapping and navigation, makes a lot of things work smoothly.

As part of security, sometimes tracking the location of devices or humans is a must, and to overcome this issue, GPS technology always helps. Nowadays, GPS has become one of the most widely used technologies in our daily lives. It plays a crucial role in navigation and location-based services. For example, when someone travels to a new place, GPS helps them find accurate routes and directions. In the automotive sector, GPS is also used in taxis and fleet vehicles for tracking, geofencing, etc. and various other operational functions that enhance efficiency and safety.

Architecture of GPS

The  GPS system is divided into three parts: Space segment, User segment and Control Segment.

Space segment: The satellites help GPS to locate the position by broadcasting the signal used by the receiver. To calculate the position, the signals of four satellites should be locked, that’s why you need to keep moving around to get a clear reception.


User segment: This segment Including GPS receivers and transmitters, including items like watches, smartphones and telematic devices. it consist of a sensitive receiver which can detect signals and then convert the data into useful information. GPS receiver helps to locate your own position.

Control segment: It consists of Earth-based monitoring stations, master control stations, and ground antennas. These components work together to track and manage satellites in orbit while continuously monitoring their signal transmissions.

GPS Security Weaknesses

From a cybersecurity perspective, GPS technology carries inherent risks because of its weak signals. These signals can be easily disrupted or completely blocked by low-power interference, making GPS highly vulnerable to intentional attacks such as jamming, and as a result, larger operation failures can happen in transportation, IoT, etc. industries. Even many receivers cannot authenticate the signals to determine whether they are coming from a legitimate source. Because of this weakness in GPS, attackers can easily transmit counterfeit GPS signals to mislead their targets. This type of manipulation is commonly known as signal spoofing.

Fake Signals, Real Consequences: How GPS Spoofing Actually Works

GPS Spoofing means tampering with the signals from the satellite and making them appear legitimate, where a malicious actor generates GPS signals to mislead GPS receivers. This spoofing scenario is possible due to the signals coming from satellites being weak when they reach the earth.  GPS spoofing can cause serious consequences in transportation, misleading the car, ship or airplane. To demonstrate how this attack works in practice, we will now explore how GPS spoofing can be performed using a HackRF One RF device.

  • Install the required dependencies and set up the HackRF device.
    $ sudo apt install gnuradio libhackrf0 hackrf libhackrf-dev
  • Clone the gps-sdr-sim repository.
    $ git clone https://github.com/osqzss/gps-sdr-sim.git
    $ cp gps-sdr-sim &&
  • Compile the source code using MAKE command
  • Download the daily BRDC GPS ephemeris file from NASA CDDIS.
  • Generate GPS signals for a specified location and time using the broadcast ephemeris file along with the desired latitude and longitude.
    $ ./gps-sdr-sim -b 8 -e brdc2700.25n -l 32.657181348472236,65.34605075320059 ,100 -d 600
  • Now Transfer GPS signals using hackrf.
    $ sudo hackrf_transfer -t gpssim.bin -f 1575420000 -s 2600000 -a 1 -x 0

Target device getting spoofed

‍‍

GPS Spoofing Mitigations

Civilian GPS signals are intrinsically insecure and vulnerable to spoofing attacks. One way to get better confidence in these signals is through techniques like Navigation Message Authentication (NMA), which can help make sure the data is from legitimate satellite sources and not from an attacker.

In real world applications, particularly in the automotive sector, GPS alone is not sufficient. A more optimal solution is to combine GPS data with other onboard sensors. For example, the vehicle motion deduced from GPS can be validated based on sensor information like accelerometers, gyroscopes, or wheel speed data. If the GPS suddenly shows a change of several kilometers, the system can check this against sensor data to see if such a movement is physically possible. If it doesn’t match, the data can be marked as suspicious.

Another useful mitigation technique is to verify position using multiple sources. The system can use more than just GPS to determine location, it can also check against other sources such as cell network triangulation or Wi-Fi positioning. Any significant difference between these sources may signify a possible spoofing attempt.

Conclusion

After exploring the fundamentals of GNSS, understanding how GPS works, and experimenting with static GPS spoofing, I realized how deeply GPS is integrated into our daily lives and critical systems. While it provides tremendous benefits for navigation and positioning, it is also susceptible to manipulation through spoofing attacks. This highlights the importance of understanding these security risks and implementing appropriate safeguards to ensure the reliability and trustworthiness of GPS-dependent systems.

Get Tested
Device, firmware and APIs scoped as one system.
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.
Author
Shubham Thorat
Senior Security Researcher
Red arrow pointing diagonally upward to the right.Red arrow pointing diagonally upward to the right.
FAQ

Questions Web Application teams ask us.

1. What is the difference between GNSS and GPS?
GNSS (Global Navigation Satellite System) is the general term for satellite navigation systems, such as GPS and GLONASS. GPS is the US system and one of several GNSS systems.
2. How does GPS work out a location?
GPS uses trilateration. Each satellite's signal tells the receiver how far away that satellite is. Three satellites give the latitude, longitude and height, and a fourth corrects timing errors.
3. What is GPS spoofing?
GPS spoofing is when an attacker sends fake GPS signals that look real. The receiver believes them and reports a false location or time.
4. Why is GPS easy to spoof?
GPS signals are very weak when they reach Earth, so a stronger local signal can easily overpower them. Most civilian receivers also cannot confirm whether a signal comes from a real satellite.
5. How can GPS spoofing be detected or prevented?
Navigation Message Authentication (NMA) helps confirm that data comes from real satellites. Systems can also check GPS against motion sensors like accelerometers and wheel speed, or against cell network and Wi-Fi positioning. If these sources disagree, the location data can be flagged as suspicious.

Keep Reading

For Security Leaders
Agentic AI Security: The Hidden Attack Surface Beyond Prompt Injection
August 25, 2026
10 min
For Security Leaders
Research & disclosures
Binwalk Path Traversal Vulnerability: Turning Firmware Analysis into Code Execution
August 26, 2026
8 min
Guides & tutorials
For Security Leaders
An Introduction to Smali
August 26, 2026
8 min
Dark scene with vertical thin orange lines resembling distant illuminated bars or streaks against a black background and a faint horizontal red glow near the bottom.