Subscriber Identity Modules (SIMs), the secure element used to connect devices to a mobile network, can pose severe security risks.

To that end, a malicious SIM could allow attackers to gather information about a device, interfere with its connectivity, and serve as entry point for further cyberattacks.

A feature known as Proactive SIM allows a SIM card to send a limited number of special commands directly to a device’s modem. One of them allows the SIM to request the execution of AT commands, the same type of commands used to control and configure modems since the 1980’s.

University of Birmingham researchers Tomasz Piotr Lisowski and Dr. Marius Muench worked with Kristian Covic, from IT security company Fuzzware, to develop the CATana toolkit to explore the dangers of SIM-originating AT commands across different devices.

CATana is a toolkit that consists of four tools enabling researchers to transceive SIM AT commands, automate testing of such commands, and inspect results from experiments.

Schneider Bold
Wide-ranging Research

The researchers investigated 26 representative devices: 18 smartphones and eight cellular-connected IoT modules, including modules commonly embedded in electric vehicle chargers, industrial equipment, and connected cars. Devices studied did not focus on any single manufacturer or operating system.

After identifying that several analyzed devices would execute SIM-originating AT commands, the researchers used CATana to demonstrate the threats of the resulting SIM AT interface, leading to the discovery of multiple security vulnerabilities. Example attacks enabled by the presence of a SIM AT interface include:

  • Re-enabling closed-down debug interfaces
  • Exfiltrating sensitive information, such as a device’s unique identifier
  • Sending messages or initiating calls
  • Obtaining arbitrary command execution capabilities on a victim’s communication processor
  • Forcing a device to downgrade from secure 4G connectivity to older and less secure 2G networks
  • Shutting down the victim device
  • Disabling cellular communications altogether

“The fascinating part here is that the proactive capabilities of a SIM and the resulting attack surface is explicitly defined in the technical specifications for cellular communication, resulting into ‘specification-compliant’ attacks,” said Muench, assistant professor in computer science at the University of Birmingham.

“Other researchers, cybersecurity experts, and leaked intelligence documents have shown some of the dangers of hostile SIMs before us,” he said. “Yet, the resulting risks (did not end up) fully mitigated. Potentially, this is because hostile SIMs are not included in most threat models; although we slowly see a promising shift here.”

Attack Scenarios

Building on their earlier work, the research team highlights four attacker scenarios leading to malicious or compromised SIMs and eSIMs, supported with precedents from real-world incidents:

  1. Remote attackers exploiting vulnerabilities in SIM software
  2. Physical attackers replacing a victim’s SIM card or installing a hardware implant
  3. Compromised operators abusing remote SIM management features
  4. Supply-chain attackers modifying SIMs during manufacturing or distribution

Researchers point out the risks of SIM-originating AT commands are especially relevant for IoT devices such as industrial equipment, vehicle systems, or routers, as these often end up locked down with only a limited number of exposed interfaces. The presence of a SIM AT interface could, therefore, serve as unforeseen entry vector for further compromising the victim device.

The study also comments on the more general risk of proactive SIMs, which can turn victim devices into surveillance tools. In their research, the team discovered on recent Android devices, a malicious SIM could force the phone to open an attacker-controlled website without any user interaction, even with a locked phone.

The researchers argue t proactive SIM features are legacy technologies built only with benign SIMs in mind. However, as technology and threat surface is evolving, features are no longer needed and create unnecessary security risks.

“At Fuzzware, we are very happy that we could support this research project,” Covic said. “Hostile SIMs are an overlooked attack vector, and it’s great that we could show this with our work.”

The researchers did not stop at solely finding the vulnerabilities. They also reached out to the GSM Association (GSMA), as well as affected chip- and device manufacturers to address the the issues.

Manufacturers’ Reaction

“It was great working together with the affected companies and GSMA,” Muench said. “Our reports (ended up) treated seriously, and key manufacturers make software updates and hardened configurations available to their customers. This will benefit billions of future SIM-enabled devices operating worldwide, including smartphones, connected vehicles, payment terminals, routers, critical infrastructure and EV charging systems.”

“The attacks we found only scratch the surface of what is possible with hostile SIM cards,” Lisowski said. “We will keep working on bringing more of the attack surface to the public light and hope to cooperate with vendors and standardization bodies to remedy the risks in today’s and future devices.”

The issues identified by the researchers as part of their study track under CVE-2025-48618, CVE-2026-57550, and CVD-2026-0122.

Click here to view the paper the team presented at the 2026 USENIX WOOT Conference on Offensive Technologies, in Baltimore, Maryland.

ISSSource

Pin It on Pinterest

Share This