Ethical Hacking News
Researchers have discovered that malicious SIM cards can be used to hijack modems, compromise phone security, and steal data. The discovery highlights the need for improved SIM security measures to prevent such attacks.
Malicious SIM cards can hijack modems and compromise phone security. Risk factors include compromised SIM software, physical tampering, operator abuse, or supply chain shenanigans. Vulnerable devices can downgrade connections to 2G, shut down phones, steal files, and execute code. Researchers found four vulnerabilities and demonstrated attacks using a toolkit called CATANA. The GSMA has assigned a tracking number CVD-2026-0122 to the issue.
The world of cellular connectivity has long been considered secure, but recent research has uncovered a new threat that could potentially compromise phone security. Researchers have found that malicious SIM cards can be used to hijack modems, downgrade connections to 2G, shut down phones, steal files, and even execute code on devices hosting them.
This discovery was made by researchers from the University of Birmingham, who tested 26 devices, including 18 smartphones and eight IoT modems. They found that nine exposed an AT command interface to the SIM, allowing a hostile SIM to issue commands to the device. The team also discovered four vulnerabilities and demonstrated attacks, including code execution, arbitrary file reads, denial of service, and downgrading connections to 2G.
The researchers were able to exploit these vulnerabilities using a toolkit called CATANA, which allowed them to manipulate the SIM's behavior. They tested the toolkit on an Autel EV charger fitted with a Quectel EC25-AFX cellular module, and successfully exploited a command injection bug in the modem's Linux-based application processor.
On another device, an Oppo Reno14 F 5G, the researchers found 198 AT commands and variants available through the SIM interface. These included commands that could power down the handset, kill its modem, or downgrade the connection to 2G. The team was also able to demonstrate file theft against a Quectel EG25-G modem by combining a malicious symbolic link with SIM-originating commands.
It's worth noting that these attacks require control of the SIM itself, which could be achieved through compromised SIM software, physical tampering, abuse of remote administration by a malicious or breached operator, or supply chain shenanigans. The researchers also found that vulnerable versions of Android allowed a hostile SIM to invoke the standardized LAUNCH BROWSER command and open an attacker-controlled website without user interaction.
The researchers disclosed their findings to Google, Oppo, Quectel, Semtech, and Qualcomm in March, followed by the GSMA in May. Qualcomm has since produced a hardened configuration that disables the SIM AT interface by default, while the GSMA is tracking the wider issue as CVD-2026-0122.
In light of this discovery, the researchers argue that the best long-term answer is to retire RUN AT and other risky proactive SIM functionality. Modern smartphones appear to have largely got the memo, but the IoT world still has some hanging up to do. The team's findings serve as a reminder of the importance of security in the world of cellular connectivity.
Related Information:
https://www.ethicalhackingnews.com/articles/Malicious-SIMs-A-Threat-to-Cellular-Connectivity-and-Data-Security-ehn.shtml
https://www.theregister.com/security/2026/08/11/malicious-sims-can-shut-down-phones-steal-files-and-drag-5g-back-to-2g/5285482
Published: Tue Aug 11 04:47:49 2026 by llama3.2 3B Q4_K_M