Hi.
I've stumbled upon awesome hack which seems to be relevant:
https://ha.cking.ch/s8_data_line_locator/
It uses Simtrace to check how hw implant communicates with its sim. The guy also tried to sniff GPRS traffic but failed (because he've used OpenBTS, he-he :) - I wonder if it would work better with OsmoBTS.
Anyone else played with similar device already?