SIM cards have long been considered secure components within our smartphones and connected devices. However, recent research reveals that if a SIM card becomes malicious or compromised, it could serve as a powerful weapon for targeting the device it resides in.
Researchers from the University of Birmingham, collaborating with cybersecurity firm Fuzzware, explored how malicious SIM cards can impact smartphones and Internet of Things (IoT) devices. They presented their findings at the 2026 USENIX WOOT Conference on Offensive Technologies in Baltimore.
The core issue revolves around a technology called Proactive SIM, which enables a SIM card to send specific commands directly to a device’s modem. Among these commands are AT commands—an archaic command set initially developed to control modems decades ago.
To evaluate the threat, the team developed a security testing toolkit called CATana, designed to simulate and analyze potential attacks. They tested 26 devices, including 18 smartphones and 8 IoT modules used in various systems like electric vehicle chargers, connected cars, and industrial machinery that communicate over cellular networks.
The results were alarming: several devices accepted AT commands originating directly from the SIM card. This vulnerability could allow a malicious SIM to perform actions such as retrieving device identification information, sending messages, making calls, reactivating hidden debugging functions, disabling cellular connectivity, or even powering down the device. In more severe scenarios, attackers could execute commands on the device’s communication processor, potentially taking full control.
Additionally, a hostile SIM could force devices to switch from secure 4G networks to the older, less secure 2G networks, increasing the risk of interception and attacks. The threat level is especially high for IoT devices like routers, vehicle systems, and industrial equipment, which are often designed with minimal interfaces to outside access. A SIM interface could provide an unexpected and dangerous pathway into these tightly secured systems.
Beyond communications, the team discovered that on recent Android phones, a malicious SIM could prompt the device to open a malicious website without user interaction, even when the phone is locked.
Various methods could enable an attacker to make a SIM malicious, including exploiting vulnerabilities in SIM software remotely, physically replacing a SIM card, compromising the mobile operator’s management systems, or tampering with SIMs during manufacturing or distribution.
Partly rooted in older industry standards, many of the Proactive SIM features were initially designed under the assumption that SIM cards could be trusted. These outdated features may now pose unnecessary risks in today’s interconnected world.
The researchers reported their findings to the GSMA and device manufacturers. Many companies have already released updates and improved device security configurations. While these steps enhance security across billions of SIM-enabled devices—from smartphones and vehicles to payment terminals and industrial controllers—they may only scratch the surface of the potential threats posed by malicious SIM cards.
Their work highlights the need for continued vigilance and stronger safeguards, as the vulnerabilities uncovered suggest that the real scope of the risk could be much broader than currently understood.








