# MTK IMEI Switcheroo (thingamabob)

**URL:** <https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750>\
**Category:** Programming and Development\
**Tags:** member-made, release\
**Created:** [May 1, 2026, 3:09am UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750 "2026-05-01T03:09:12Z")\
**Posts on this page:** 20\
**Page:** 4

<div class="post-metadata">

**Author:** ![farrict](https://jtechforums.org/user_avatar/jtechforums.org/farrict/32/5583_2.png) [@farrict](https://jtechforums.org/u/farrict)\
**Post date:** [May 3, 2026, 10:08pm UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/62 "2026-05-03T22:08:49Z")

</div>

[Yup.](https://jtechforums.org/t/new-dumberos-dumbdroid-device/6197/11)

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [May 3, 2026, 10:36pm UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/63 "2026-05-03T22:36:55Z")

</div>

From a root shell run

```bash
dd if=/dev/block/by-name/nvdata of=/sdcard/nvdata.img

```

Then you should have nvdata.img in internal storage.

---

<div class="post-metadata">

**Author:** ![Yidish](https://jtechforums.org/user_avatar/jtechforums.org/yidish/32/1211_2.png) [@Yidish](https://jtechforums.org/u/Yidish)\
**Post date:** [May 4, 2026, 12:59am UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/64 "2026-05-04T00:59:37Z")

</div>

The phone must be rooted? Or I can put in the system so it will work without root?

---

<div class="post-metadata">

**Author:** ![sh7411usa](https://jtechforums.org/user_avatar/jtechforums.org/sh7411usa/32/4389_2.png) [@sh7411usa](https://jtechforums.org/u/sh7411usa)\
**Post date:** [May 4, 2026, 2:57am UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/65 "2026-05-04T02:57:26Z")

</div>

@ars18 ty for reverse engineering the crypto! I wonder if you looked into bt address and wifi mac as well?

---

<div class="post-metadata">

**Author:** ![sh7411usa](https://jtechforums.org/user_avatar/jtechforums.org/sh7411usa/32/4389_2.png) [@sh7411usa](https://jtechforums.org/u/sh7411usa)\
**Post date:** [May 4, 2026, 3:51am UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/66 "2026-05-04T03:51:07Z")

</div>

Additionally, thought it would be nice to add an IMEI generator to the app, going to dump my research here.

Graphic credit imei.info link below

 ![image](https://jtechforums.org/uploads/default/original/2X/2/2daca6d89f91ab2a6bdd0efa7fd0e49647ec541d.jpeg)

IMEI is structured in 3 parts:

1. TAC (Type Allocation Code) First 8 Digits. The first two digits identify cert. region (01 is US), next 6 identify manufacturer and model. For instance, all Kyocera E4810 should start with 01558800, 01 for USA, 558800 for Kyocera E4810.

2. SNR (Serial number) 6 digits that uniquely identify your device.

3. CD (Check Digit) 1 digit that is calculated from the preceding 14 using Luhn (mod 10) algo. (Implemented in attached python script)

Info on the structure of IMEI mainly from here:

> **[TAC Database: A Complete Guide to TAC IMEI Info and IMEI TAC Models - News -...](https://www.imei.info/news/tac-database-complete-guide-tac-imei-info-and-imei-tac-models/)**

Here is an extensive list of TAC codes that can be parsed in to an offline DB.

> **[82671548-TAC-Code-List.pdf](https://www.freecalypso.org/pub/GSM/IMEI/82671548-TAC-Code-List.pdf)**
>
> 2.73 MB

TACS can also be sourced here:

[https://swappa.com/imei/tac](https://swappa.com/imei/tac)

So a basic generator would allow you to choose a known TAC, (like 01558800 for Kyocera E4810 for example), generate a random 6 digit number (like say, um, 123456) and calculate a luhn for that (which happens to be 3 for this example. Following the examples, the resulting IMEI would be 01558800 - 123456 - 3).

Here is a python script that checks IMEI numbers. It contains a function to generate the luhn check digit, as well as a very tiny hardcoded tac db.

```python
import sys

# Tiny hardcoded TAC DB
TAC_DB = {
  "35875110": "Apple iPhone 11",
  "35299209": "Apple iPhone 8",
  "35744105": "Samsung Galaxy S4",
  "35903908": "Samsung Galaxy S8",
  "35174605": "Google Galaxy Nexus",
  "35824005": "Google Nexus 5",
  "35447909": "Nokia 1",
  "35151304": "Nokia E72-1",
  "01558800": "Kyocera Dura Extreme E4810"
}

# Reporting Body Identifiers (First 2 digits)
RBI_MAP = {
  "01": "CTIA (USA)",
  "35": "BABT (UK/Global)",
  "86": "TAF (China)",
  "91": "MSAI (India)",
  "99": "GHA (Multi-RAT / Global)"
}

def calculate_luhn(number_str):
#Calculates the expected 15th digit for a 14-digit sequence.
  digits = [int(d) for d in number_str]
  total_sum = 0
  for i, digit in enumerate(digits):
    if i % 2 != 0:
        doubled = digit * 2
        total_sum += (doubled - 9) if doubled > 9 else doubled
    else:
        total_sum += digit
  return (10 - (total_sum % 10)) % 10

def analyze_imei(imei):
  imei = imei.strip().replace(" ", "").replace("-", "")
  if len(imei) != 15 or not imei.isdigit():
    return f"Error: {imei} is not a valid 15-digit IMEI format."
  tac = imei[:8]
  rbi = imei[:2]
  serial = imei[8:14]
  check_digit = int(imei[14])

  # Analysis
  region = RBI_MAP.get(rbi, "Unknown / Other Body")
  model = TAC_DB.get(tac, "Model not in local database")
  expected_luhn = calculate_luhn(imei[:14])
  luhn_status = "VALID" if expected_luhn == check_digit else f"INVALID (Expected {expected_luhn})"

  result = [
    f"\n--- Analysis for: {imei} ---",
    f" [+] Region (RBI): {rbi} -> {region}",
    f" [+] Make/Model: {model} (TAC: {tac})",
    f" [+] Device Serial: {serial}",
    f" [+] Luhn Check: {luhn_status}",
  ]

  return "\n".join(result)

if _name_ == “_main_”:

# Check if arguments were passed
if len(sys.argv) < 2:
    print("Usage: python imei_analyzer.py <imei1> <imei2> ...")
    print("Example: python imei_analyzer.py 358751101234567 357441051234560")
else:
    for arg in sys.argv[1:]:

        print(analyze_imei(arg))

```

Try the script using our above E4810 example:

```auto
 python imei_checker.py 015588001234563

```

You can also test with an invalid luhn by changing the last digit randomly.

This info can easily be used to implement a basic IMEI generator in the app that should allow for a basic “verizon” (using a known TAC) or other IMEI.

**THIS POST IS FOR EDUCATIONAL PURPOSES** Changing an IMEI can be unethical and illegal in your area. The poster declaims any responsibility for your actions.

---

<div class="post-metadata">

**Author:** ![kosherboy](https://jtechforums.org/user_avatar/jtechforums.org/kosherboy/32/292_2.png) [@kosherboy](https://jtechforums.org/u/kosherboy)\
**Post date:** [May 4, 2026, 4:53am UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/68 "2026-05-04T04:53:31Z")

</div>

Wow cool research.

How about building in imei.info so that the user can pick a phone and the app will pull a imei from that site. Obviously the app will need access to the internet (as opposed to @sh7411usa’s idea…).

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [May 4, 2026, 6:57am UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/69 "2026-05-04T06:57:04Z")

</div>

Wdym put in system? You’re building a ROM and wanna make it w system app? That should work too cuz system apps have root access but I don’t know

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [May 4, 2026, 6:57am UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/70 "2026-05-04T06:57:38Z")

</div>

Thanks so much for the research! I love the idea! I’ll try to add it later today.

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [May 4, 2026, 11:28am UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/71 "2026-05-04T11:28:43Z")

</div>

Done!

[https://github.com/flipphoneguy/mtk-imei-switcheroo-app](https://github.com/flipphoneguy/mtk-imei-switcheroo-app)

> **[Release v1.1.0 · flipphoneguy/mtk-imei-switcheroo-app](https://github.com/flipphoneguy/mtk-imei-switcheroo-app/releases/tag/v1.1.0)**
>
> Added option to override safetyguard to flash bands when the app fails to detect the version. See the README for more details. @shimonkohn

I used an iphone that’s sold in the US for Verizon

Can also generate kosher IMEIs (for Israeli kosher SIMs). Got the list from cellular Israel

I tested basic functionality. I didn’t test Verizon or kosher SIM.

Lmk if there’s any issues

---

<div class="post-metadata">

**Author:** ![sh7411usa](https://jtechforums.org/user_avatar/jtechforums.org/sh7411usa/32/4389_2.png) [@sh7411usa](https://jtechforums.org/u/sh7411usa)\
**Post date:** [May 4, 2026, 12:45pm UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/72 "2026-05-04T12:45:07Z")

</div>

Amazing!! Can’t wait to test it out! 🙏

---

<div class="post-metadata">

**Author:** ![sh7411usa](https://jtechforums.org/user_avatar/jtechforums.org/sh7411usa/32/4389_2.png) [@sh7411usa](https://jtechforums.org/u/sh7411usa)\
**Post date:** [May 4, 2026, 1:06pm UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/73 "2026-05-04T13:06:18Z")

</div>

I’d suggest one more feature: Add a launch method via dialer code (you can do `*#*#1122#*#*` like some other devices), and an option to hide the app from the launcher. This will be perfect for including as a system app in a ROM. Although I understand that including in a non rooted ROM will require using changing your access approach to priv-app instead of su runtime (because su is not included in non rooted roms, obviously).

Also - large size TAC db available for easy CSV download here:

> **[Osmocom TAC Database](http://tacdb.osmocom.org/)**

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [May 4, 2026, 1:10pm UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/74 "2026-05-04T13:10:53Z")

</div>

I found that. First of all that doesn’t have kosher numbers and secondly I didn’t want my app being a few mb. I love a few kb!

Regarding building into ROM, I’m not sure if anyone would use that. And if yes, someone building a ROM should be able to do it themselves. The only things he’ll have to change is that you mentioned. It’s open source after all (it maybe it’s just that I’m lazy 🤣)

---

<div class="post-metadata">

**Author:** ![ars18](https://jtechforums.org/user_avatar/jtechforums.org/ars18/32/11805_2.png) [@ars18](https://jtechforums.org/u/ars18)\
**Post date:** [May 4, 2026, 1:12pm UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/75 "2026-05-04T13:12:10Z")

</div>

> [@neshomoleh](#):
>
> I would be happy to share the partitions for testing and documentation. Could you guide me on the best way to do it? Should I use **MTK Client** on a PC, or is there a way to dump them directly from the device using **root access**

mtkclient would be best option if that’s easy for you.

Partitions I need to claim full repo support:

- nvram
- nvdata
- nvcfg
- md1img

But don’t upload publicly, will have your imei in it.

---

<div class="post-metadata">

**Author:** ![ars18](https://jtechforums.org/user_avatar/jtechforums.org/ars18/32/11805_2.png) [@ars18](https://jtechforums.org/u/ars18)\
**Post date:** [May 4, 2026, 1:13pm UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/76 "2026-05-04T13:13:30Z")

</div>

I started, but didn’t know if it would vary with multiple devices so I put it on hold for now. Perhaps no difference.

How important is it?

---

<div class="post-metadata">

**Author:** ![ars18](https://jtechforums.org/user_avatar/jtechforums.org/ars18/32/11805_2.png) [@ars18](https://jtechforums.org/u/ars18)\
**Post date:** [May 4, 2026, 1:14pm UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/77 "2026-05-04T13:14:37Z")

</div>

Nice idea. Will definitely leave that to the @flipphoneguy app.

I’m also nervous to add something too suggestive for actually switching I’m already getting hit too hard with the gplay repo.

I see he did it already

---

<div class="post-metadata">

**Author:** ![ars18](https://jtechforums.org/user_avatar/jtechforums.org/ars18/32/11805_2.png) [@ars18](https://jtechforums.org/u/ars18)\
**Post date:** [May 4, 2026, 1:20pm UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/78 "2026-05-04T13:20:04Z")

</div>

> [@flipphoneguy](#):
>
> That should work too cuz system apps have root access but I don’t know

> [@sh7411usa](#):
>
> This will be perfect for including as a system app in a ROM.

With root, system app no issue. But without… You will need multiple edits to the app and I really feel like selinux will not be a fun time.

For roms that have root would be great as default included.

---

<div class="post-metadata">

**Author:** ![sh7411usa](https://jtechforums.org/user_avatar/jtechforums.org/sh7411usa/32/4389_2.png) [@sh7411usa](https://jtechforums.org/u/sh7411usa)\
**Post date:** [May 4, 2026, 1:31pm UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/79 "2026-05-04T13:31:09Z")

</div>

> [@ars18](#):
>
> How important is it?

Not _mammesh vichtig_, just an idea.

> [@ars18](#):
>
> I really feel like selinux will not be a fun time

No, it won’t. Like really. However - it would be similar to ROM development in general. Lots of trial and error and AI prompts. But, as the wise man once said:

> [@flipphoneguy](#):
>
> And if yes, someone building a ROM should be able to do it themselves.

Point is, for _shleimus_, I thought it would be nice to include the app in 613, with the ability to restore IMEI, Wi-Fi mac, and BT address.

In conclusion:

> [@flipphoneguy](#):
>
> maybe it’s just that I’m lazy 🤣

You will notice that I haven’t offered to do it myself. 😜

---

<div class="post-metadata">

**Author:** ![ars18](https://jtechforums.org/user_avatar/jtechforums.org/ars18/32/11805_2.png) [@ars18](https://jtechforums.org/u/ars18)\
**Post date:** [May 4, 2026, 1:33pm UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/80 "2026-05-04T13:33:53Z")

</div>

> [@sh7411usa](#):
>
> Point is, for _shleimus_, I thought it would be nice to include the app in 613, with the ability to restore IMEI, Wi-Fi mac, and BT address.

Gotcha. Yeah, that should be simple enough. I’ll try and figure it out. I will have to label each phone process separate unless I can prove all supported so far is the same, or have anecdotal evidence from others.

---

<div class="post-metadata">

**Author:** ![sh7411usa](https://jtechforums.org/user_avatar/jtechforums.org/sh7411usa/32/4389_2.png) [@sh7411usa](https://jtechforums.org/u/sh7411usa)\
**Post date:** [May 4, 2026, 1:36pm UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/81 "2026-05-04T13:36:26Z")

</div>

If you figure out the F21, I can check for you on some other MTK devices.

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [May 4, 2026, 1:40pm UTC](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750/82 "2026-05-04T13:40:04Z")

</div>

I found that on my device it’s plain bytes. Not encoded at all! Just 2 weird bytes aa XX where it’s always aa and the XX is different in every file (bt Mac gps). I’ve seen on XDA someone saying he modified those files and it didn’t persist in reboot. Maybe it got corrupted so went back to factory. I can try later today on my phone. I also don’t know if this is just my phone or app MT67xxx

[Previous page](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750.md?page=3)

[Next page](https://jtechforums.org/t/mtk-imei-switcheroo-thingamabob/6750.md?page=5)
