Researchers from the University of Birmingham and Fuzzware revealed that proactive SIM card features and legacy AT commands expose smartphones, EV chargers, and IoT devices to remote hijacking and code execution.

Malicious SIM Cards Can Hijack Smartphones, EV Chargers, and Connected Devices

The420 Web Correspondent
6 Min Read

Cybersecurity researchers from the University of Birmingham and security firm Fuzzware revealed at the USENIX WOOT (Workshop on Offensive Technologies) Conference in Baltimore that standard SIM cards pose severe, largely unmitigated security risks to modern cellular devices. Contrary to the widespread perception that Subscriber Identity Module (SIM) cards are static identification chips, they operate as fully functioning mini-computers capable of running autonomous software and interacting directly with device hardware. When compromised or maliciously designed, these modules can be leveraged to harvest sensitive user data, manipulate network connectivity, and serve as an initial foothold for broader cyber intrusions across consumer and industrial electronics.

The primary vulnerability stems from a standardized feature known as Proactive SIM, which grants the SIM card permission to send proactive operational commands directly to a device’s internal cellular modem. Among these capabilities is the execution of Hayes AT commands, a legacy modem control protocol originating in the 1980s that remains deeply integrated into modern cellular technical specifications. Because these commands are processed directly at the modem layer, they bypass traditional operating system security boundaries, allowing a rogue SIM to issue low-level instructions without requiring user authentication, screen interaction, or explicit permission from the operating system.

Empirical Testing Across Smartphones and Industrial IoT Hardware

To demonstrate the real-world implications of these SIM-originating vulnerabilities, the research team developed a specialized analysis tool called CATana to audit 26 representative commercial devices. The evaluation suite spanned 18 consumer smartphones running various operating systems and eight cellular IoT modules commonly deployed in critical infrastructure, including electric vehicle (EV) charging stations, connected automotive systems, and industrial routers. The findings confirmed that a significant portion of modern cellular hardware blindly accepts and executes unauthorized AT commands originating from the SIM card slot.

The practical attacks demonstrated by the researchers highlight severe operational risks across diverse device categories. On recent Android smartphones, the team demonstrated that a malicious SIM card could force the device to open an attacker-controlled web URL without any user interaction, even while the phone was locked. Across broader IoT infrastructure and EV chargers, compromised SIMs were shown to trigger forced remote device shutdowns, induce network downgrades to legacy 2G connections that lack modern encryption, steal stored confidential files, and execute arbitrary code on connected host processors.

Supply Chains and Remote Management as Critical Attack Pathways

The study categorized four distinct real-world threat models through which an attacker could deploy or exploit malicious SIM cards across cellular ecosystems. Attackers can remotely exploit unpatched software vulnerabilities existing within the SIM card’s own operating system, physically swap legitimate SIM cards with compromised hardware implants, or execute supply-chain interdictions to modify SIM cards during manufacturing and distribution. Additionally, rogue telecom operators or compromised administrative accounts can abuse remote SIM management features to push malicious over-the-air updates directly to installed eSIMs and physical SIM cards.

These vector pathways present exceptional risks for Internet of Things (IoT) hardware, such as electric vehicle charging networks and industrial control systems. Infrastructure operators typically fortify IoT devices by disabling physical ports like USB interfaces and locking down external software entry points. However, because the SIM card slot is treated as an inherently trusted internal component, security architectures rarely monitor or restrict command flows originating from the cellular modem interface, leaving critical municipal and energy infrastructure exposed to stealthy hardware-level attacks.

Coordinated Disclosure and the Push for Modernized Threat Models

Lead researcher Dr. Marius Muench, Assistant Professor in Computer Science at the University of Birmingham, emphasized that the underlying problem is rooted in cellular standards that define proactive SIM capabilities without anticipating adversarial threat models. Because SIM cards were historically assumed to be trusted entities provided solely by legitimate network operators, threat models for mobile phones and IoT hardware routinely overlooked the possibility of a hostile SIM. Researchers argue that many proactive SIM features represent obsolete legacy technologies that introduce unnecessary risk into modern cyber-physical ecosystems.

Prior to public disclosure at the WOOT conference, the research team engaged in coordinated vulnerability disclosure with affected chipset manufacturers, device vendors, and the global mobile communications trade body GSMA. In response, several major hardware vendors and chipmaker partners have initiated firmware updates and tightened software configurations designed to sanitize or block unauthorized SIM-originating AT commands. Cybersecurity experts stress that long-term mitigation will require standardizing threat models that treat SIM cards as potentially untrusted peripherals and deprecating redundant legacy commands across global telecommunication specifications.

Stay Connected