Birmingham.Ac.Uk
Malicious SIM Cards Exploit Vulnerabilities in Smartphones and IoT Devices
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Researchers from the University of Birmingham presented findings on the security risks posed by malicious SIM cards at the 2026 USENIX WOOT Conference. Their study revealed that 9 out of 26 analyzed devices, including smartphones and IoT modules, expose a SIM AT interface that can be exploited through SIM-originating AT commands. The CATana toolkit was developed to demonstrate these vulnerabilities, resulting in the discovery of four significant security flaws, including command execution and Denial-of-Service attacks. The risks are particularly concerning for IoT devices, which often have limited interfaces. Despite previous warnings about hostile SIMs, the threats remain largely unaddressed in current threat models. The research emphasizes the need for hardening or disabling the SIM AT interface to mitigate these risks.
Key Points: • Nine out of 26 devices analyzed expose a vulnerable SIM AT interface. • Four significant vulnerabilities were discovered, including command execution and DoS. • The CATana toolkit was developed to explore and demonstrate these SIM-originating threats.