Birmingham.Ac.Uk
Malicious SIM Cards Exploit Vulnerabilities in Smartphones and IoT Devices
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Researchers from the University of Birmingham and Fuzzware have discovered severe vulnerabilities in SIM cards that can hijack smartphones and IoT devices, including electric vehicle chargers. The vulnerabilities stem from a feature called 'Proactive SIM,' which allows SIM cards to issue commands directly to device modems using AT commands. Testing 26 devices, including 18 smartphones and 8 IoT modules, the team found that several devices were susceptible to attacks that could lead to code execution, data theft, and downgrading of network connections. The toolkit used for these tests, named CATana, revealed that attackers could exploit these vulnerabilities without user interaction. The findings were presented at the 2026 USENIX WOOT Conference, highlighting the need for improved threat modeling to include hostile SIMs. The research indicates that hostile SIMs could enter the market through compromised software updates or supply chain issues, posing a significant risk to connected infrastructure.
Key Points: • Malicious SIM cards can exploit vulnerabilities in smartphones and IoT devices. • The 'Proactive SIM' feature allows SIMs to issue commands directly to device modems. • The CATana toolkit demonstrated severe security flaws across 26 tested devices.