Malicious SIM cards can hijack cellular IoT modems via spec-compliant commands
Researchers demonstrate that 'proactive' SIM functionality allows attackers to execute commands on host devices, posing a systemic risk to industrial IoT.
Researchers from the University of Birmingham and Fuzzware have demonstrated that malicious SIM cards can hijack the modems of cellular-connected devices by abusing standardized 'proactive SIM functionality.' The findings, presented at the 2026 USENIX WOOT Conference on Offensive Technologies in Baltimore, reveal a critical vulnerability in how devices trust the SIM module.
Using a specialized toolkit called CATANA, the research team—including Tomasz Piotr Lisowski, Dr. Marius Muench, and Kristian Covic—showed that attackers can leverage the 'RUN AT' command. Defined in the 3GPP TS 31.111 technical specification, this feature allows a SIM card to request the execution of AT commands directly on the host modem. By exploiting this, a malicious SIM can trigger code execution, steal files, or launch denial-of-service attacks. The team tested 26 devices, consisting of 18 smartphones and 8 IoT modems, finding that IoT modems are significantly more vulnerable to these attacks than modern smartphones.
The 'Proactive' Blind Spot
SIM cards are widely perceived as passive identity modules that simply store credentials. However, cellular technical specifications include 'proactive' capabilities that allow the SIM to initiate actions on the device. While smartphone manufacturers have largely mitigated these risks over time, the IoT ecosystem remains exposed. Industrial routers, telematics units, and other connected infrastructure often rely on embedded cellular modules that leave these legacy interfaces open and unprotected.
"The fascinating part here is that the proactive capabilities of a SIM and the resulting attack surface is explicitly defined in the technical specifications for cellular communication," said Marius Muench of the University of Birmingham.
Systemic Risks to Infrastructure
This research highlights a major blind spot in current IoT threat models. Because the attacks are 'specification-compliant,' they often bypass traditional security checks that look for anomalous traffic or unauthorized access. The ability to achieve remote code execution on critical infrastructure via a compromised SIM—whether through supply chain attacks or malicious operators—poses a significant systemic risk to cellular IoT deployments.
Beyond industrial hardware, the researchers identified risks to mobile users. A specific vulnerability in Android (CVE-2025-48618) allowed malicious SIMs to use the LAUNCH BROWSER command to open attacker-controlled websites. This action occurred without any user interaction and could be triggered even while the device was locked.
Future Outlook
As cellular IoT continues to expand into critical infrastructure, the reliance on trusted hardware modules like SIM cards is being called into question. The industry must now determine how to restrict proactive SIM commands without breaking essential network functionality. For now, the research serves as a warning that the very standards designed to ensure global connectivity are being used as a backdoor into the heart of connected devices.