Malicious SIM Cards Exploit Proactive Functionality to Hijack Devices
Researchers from the University of Birmingham and Fuzzware have uncovered critical vulnerabilities in how SIM cards interact with smartphones and IoT devices, enabling attackers to execute code, steal data, or force devices onto insecure 2G networks. The findings, presented at the USENIX WOOT conference in Baltimore, highlight risks in proactive SIM functionality a feature designed to let SIMs issue commands to their host devices.
Using a toolkit called CATANA, the team led by Tomasz Piotr Lisowski, Marius Muench, and Kristian Covic tested 26 devices (18 smartphones and 8 IoT modems). Nine devices exposed an AT command interface to the SIM, with IoT modems being particularly vulnerable (seven of eight tested). The attacks exploited RUN AT, a command that allows SIMs to execute legacy AT instructions, originally designed for modems in the 1980s.
Key vulnerabilities demonstrated include:
- Code execution on an Autel EV charger via a Quectel EC25-AFX modem.
- Denial-of-service attacks, including forcing an Oppo Reno14 F 5G to power down or lock onto 2G (a downgrade resistant to standard fixes like airplane mode).
- File theft from a Quectel EG25-G modem by combining malicious symbolic links with SIM commands.
- Unauthorized browser launches on vulnerable Android versions (CVE-2025-48618), patched in December 2025 for Android 13–16.
The attacks require SIM control, achievable through compromised software, physical tampering, or supply chain manipulation. While modern smartphones have reduced exposure, IoT devices remain at higher risk.
The researchers disclosed findings to Google, Oppo, Quectel, Semtech, Qualcomm, and the GSMA. Qualcomm now disables the SIM AT interface by default, and the GSMA tracks the issue as CVD-2026-0122. The team advocates retiring RUN AT and other high-risk proactive SIM features to mitigate long-term threats.
Semtech cybersecurity rating report: https://www.rankiteo.com/company/semtech
Quectel cybersecurity rating report: https://www.rankiteo.com/company/quectel-wireless-solutions
"id": "SEMQUE1786444258",
"linkid": "semtech, quectel-wireless-solutions",
"type": "Vulnerability",
"date": "5/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'EV Charging',
'name': 'Autel',
'type': 'Company'},
{'industry': 'Smartphones',
'name': 'Oppo',
'type': 'Company'},
{'industry': 'IoT Modems',
'name': 'Quectel',
'type': 'Company'},
{'industry': 'Semiconductors/IoT',
'name': 'Semtech',
'type': 'Company'},
{'industry': 'Semiconductors/Chipsets',
'name': 'Qualcomm',
'type': 'Company'},
{'industry': 'Technology/Software',
'name': 'Google (Android)',
'type': 'Company'}],
'attack_vector': 'Malicious SIM cards (proactive SIM functionality, RUN AT '
'commands)',
'data_breach': {'data_exfiltration': 'Yes (file theft demonstrated)',
'personally_identifiable_information': 'Potential (not '
'confirmed)',
'sensitivity_of_data': 'Potentially high (if PII or system '
'files were accessed)',
'type_of_data_compromised': 'Files, device control data'},
'date_publicly_disclosed': '2026-08 (USENIX WOOT conference)',
'description': 'Researchers from the University of Birmingham and Fuzzware '
'uncovered critical vulnerabilities in how SIM cards interact '
'with smartphones and IoT devices, enabling attackers to '
'execute code, steal data, or force devices onto insecure 2G '
'networks. The vulnerabilities exploit proactive SIM '
'functionality, a feature designed to let SIMs issue commands '
'to their host devices.',
'impact': {'data_compromised': 'File theft, unauthorized data access',
'downtime': 'Denial-of-service (device power down, 2G network '
'lock)',
'identity_theft_risk': 'Potential (if PII was accessed)',
'operational_impact': 'Device hijacking, network downgrade, '
'unauthorized browser launches',
'systems_affected': 'Smartphones, IoT modems, EV chargers'},
'initial_access_broker': {'entry_point': 'Compromised SIM cards (software, '
'physical tampering, or supply chain '
'manipulation)',
'high_value_targets': 'IoT modems, smartphones with '
'vulnerable Android versions'},
'investigation_status': 'Disclosed to vendors, patches issued for some '
'affected systems',
'lessons_learned': 'Proactive SIM functionality and legacy AT commands pose '
'significant security risks, especially in IoT devices. '
'Modern smartphones are less exposed, but IoT modems '
'remain vulnerable.',
'post_incident_analysis': {'corrective_actions': 'Patches for Android, '
'disabling SIM AT '
'interfaces, advocacy to '
'retire RUN AT commands',
'root_causes': 'Legacy proactive SIM functionality '
'(RUN AT commands) and exposed AT '
'command interfaces in IoT '
'modems/smartphones'},
'recommendations': 'Retire high-risk proactive SIM features like RUN AT, '
'disable SIM AT interfaces by default, and apply patches '
'for vulnerable Android versions. Enhance supply chain '
'security for SIM cards.',
'references': [{'source': 'USENIX WOOT Conference'},
{'source': 'CVE-2025-48618'},
{'source': 'GSMA CVD-2026-0122'}],
'response': {'communication_strategy': 'Disclosure to Google, Oppo, Quectel, '
'Semtech, Qualcomm, and GSMA',
'containment_measures': 'Disabling SIM AT interface by default '
'(Qualcomm), GSMA tracking '
'(CVD-2026-0122)',
'remediation_measures': 'Patches for Android 13–16 '
'(CVE-2025-48618), advocacy to retire '
'RUN AT commands'},
'stakeholder_advisories': 'Vendors (Google, Oppo, Quectel, Semtech, Qualcomm) '
'and GSMA notified. Qualcomm disabled SIM AT '
'interface by default.',
'title': 'Malicious SIM Cards Exploit Proactive Functionality to Hijack '
'Devices',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'Proactive SIM functionality (RUN AT commands, AT '
'command interface)'}