researchers-reveal-malicious-sim-cards-hijack-smartphones,-ev-chargers-and-iot-devices
Researchers reveal malicious SIM cards hijack smartphones, EV chargers and IoT devices

Researchers reveal malicious SIM cards hijack smartphones, EV chargers and IoT devices

A compromised SIM card could give attackers far more control over a smartphone, vehicle system, industrial device or router than previously understood, according to research from the University of Birmingham. The study identifies a largely overlooked attack surface in cellular devices: commands sent directly from a SIM to a modem through a telecommunications feature known as Proactive SIM. In testing, researchers found that these SIM-originating commands could expose sensitive data, manipulate connectivity, revive disabled interfaces and, in some cases, provide a route to arbitrary command execution on a device’s communication processor.

SIM cards are commonly treated as passive identity credentials that authenticate a subscriber to a mobile network. In reality, modern SIMs contain their own software and can interact with the host device through standardized mechanisms. Proactive SIM, also known as the SIM Application Toolkit in many implementations, enables a card to request that the phone or modem perform certain operations. These operations can include displaying messages, initiating calls, sending text messages, opening network services or managing connectivity. The feature was designed for legitimate services offered by mobile operators, but its ability to issue commands creates a powerful interface that may be abused when a SIM is malicious, compromised or physically replaced.

Researchers Tomasz Piotr Lisowski and Dr Marius Muench of the University of Birmingham, working with Kristian Covic of the cybersecurity company Fuzzware, developed a toolkit called CATana to investigate this interface. Their work focused on a specific capability that allows a SIM to request the execution of AT commands. AT commands are a long-established control language used to configure and operate modems, dating back to the 1980s. Depending on the implementation, they can affect network registration, device settings, messaging, calls, radio technologies and diagnostic functions. Although the commands are normally exchanged between trusted software components and a modem, the researchers found that some devices allowed them to originate from the SIM itself.

The team examined 26 representative products, including 18 smartphones and eight cellular-enabled Internet of Things modules. The devices came from different manufacturers and operating-system environments, while the IoT equipment included modules designed for electric-vehicle chargers, industrial systems, connected vehicles and other embedded applications. CATana was used to identify how devices processed SIM-originating commands and whether those commands were filtered, restricted or passed into more privileged modem interfaces. The results showed that several tested products exposed a SIM AT interface, creating a pathway that was not necessarily visible to users or administrators.

The consequences varied according to the device and modem architecture, but the researchers demonstrated a range of potentially serious attacks. A hostile SIM could re-enable debug interfaces that had previously been shut down, extract sensitive information such as a device’s unique identifier, send messages or place calls, and interfere with cellular registration. Other attacks could force a device to abandon secure 4G connectivity in favor of older 2G networks, whose weaker security properties have made them a target for interception and downgrade attacks. In some cases, researchers obtained arbitrary command-execution capabilities on the communication processor, the component responsible for cellular networking and often connected to other parts of the device.

The communication processor is a particularly important target because it may have access to functions that are isolated from ordinary applications. On smartphones, the modem typically handles radio communication, subscriber authentication and network protocols. On IoT products, it may control the only external connection available to an otherwise locked-down system. A vulnerability in the modem’s command handling can therefore become a bridge from the cellular interface into the wider device. The risk is heightened in industrial equipment, routers, vehicle systems and charging stations, where hardware may operate unattended for years and receive limited security monitoring.

The study also highlights a broader danger associated with proactive SIM features: a malicious card may be able to turn a phone into a surveillance or interaction tool without obvious user consent. During their work, the researchers found that recent Android devices could be induced to open an attacker-controlled website without user interaction, including while the handset was locked. Depending on the device’s implementation, other proactive functions could trigger calls, messages or changes in network behavior. These capabilities do not necessarily require the attacker to exploit the phone’s main operating system; instead, they rely on commands that the cellular standards explicitly allow a SIM to send.

The researchers describe four routes by which an attacker might obtain or influence a SIM or eSIM. A remote attacker could exploit software vulnerabilities within a SIM. Someone with physical access could replace a card or install a hardware implant. A compromised mobile operator could misuse remote SIM-management systems, while a supply-chain attacker could modify cards during manufacturing, personalization or distribution. These scenarios are not merely theoretical: the researchers cite previous incidents, cybersecurity findings and leaked intelligence documents showing that hostile or compromised SIMs have been considered in real-world operations. Yet many device threat models still assume that a SIM is trusted.

Lisowski, Muench and Covic argue that several proactive SIM capabilities are legacy technologies designed at a time when cards were expected to behave benignly. As mobile systems have become more complex and SIMs have gained remote-management functions, the same capabilities now represent an unnecessary or insufficiently controlled attack surface. The team reported its findings to the GSM Association and affected chip and device manufacturers. According to the researchers, key manufacturers have issued software updates or hardened configurations, potentially reducing the risk for future devices and protecting a broad ecosystem that includes smartphones, payment terminals, connected cars, routers, critical infrastructure and electric-vehicle charging systems.

The findings will be presented at the 2026 USENIX WOOT Conference on Offensive Technologies in Baltimore, where the research paper, “CATANA: On the Dangers of SIM-Originating AT Commands,” will be published as an open-access work. The researchers emphasize that the attacks demonstrated so far may represent only a fraction of the capabilities exposed by hostile SIMs. The disclosed issues are tracked under CVE-2025-48618, CVE-2026-57550 and CVD-2026-0122, underscoring the need for manufacturers and standards bodies to treat SIM-originating commands as an explicit security boundary rather than an ordinary part of cellular functionality.

Subject of Research: Security risks posed by malicious or compromised SIM and eSIM cards, particularly SIM-originating AT commands and Proactive SIM interfaces.

Article Title: Malicious SIM Cards Can Take Control of Modems and Expose a Hidden Cellular Attack Surface

References: Tomasz Piotr Lisowski, Kristian Covic and Marius Muench, “CATANA: On the Dangers of SIM-Originating AT Commands,” presented at the 2026 USENIX WOOT Conference on Offensive Technologies. Related issue identifiers: CVE-2025-48618, CVE-2026-57550 and CVD-2026-0122.

Keywords

SIM security, eSIM, cybersecurity, mobile networks, Proactive SIM, SIM Application Toolkit, AT commands, modem security, smartphones, IoT security, connected vehicles, industrial systems, 2G downgrade attacks, cellular communications, CATana, telecommunications.

Tags: cellular device attack surfaceindustrial device SIM vulnerabilitiesIoT device SIM-based attacksMalicious SIM card vulnerabilitiesmobile network security threatsProactive SIM security risksSIM application toolkit misuseSIM card command injection attacksSIM card software and remote controlSIM card-based remote command executionsmartphone SIM card exploitationvehicle and EV charger hacking via SIM