Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G
Researchers find standards-compliant functionality can be abused to hijack modems, downgrade connections, and even execute code
Malicious SIM cards have the potential to disrupt smartphones and cellular devices, stealing data, executing malicious code, and even reverting connections to outdated 2G networks. This is due to a feature known as proactive SIM functionality, which allows SIM cards to issue commands to the devices they're embedded in. Researchers from the University of Birmingham, along with Fuzzware, have developed a toolkit called CATANA to explore the capabilities of malicious SIM cards.
Using CATANA, they tested 26 devices, including smartphones and IoT modems, and discovered that nine devices exposed an AT command interface to the SIM. The IoT kit, in particular, was found to accommodate seven out of eight modems. The researchers identified four vulnerabilities and demonstrated attacks including code execution, arbitrary file reads, denial of service, and downgrading connections to 2G.
These attacks are considered specification-compliant, meaning they adhere to the technical specifications for cellular communication. Despite previous research and leaked intelligence documents showcasing the risks, hostile SIMs are not currently a common concern in threat models. The researchers tested their attacks on an Autel EV charger and an Oppo Reno14 F 5G, exploiting AT command bugs in the modem's Linux-based application processor.
On the Oppo Reno14 F 5G, they successfully downgraded the connection to 2G, a feat that proved difficult to reverse with standard phone settings. Although the attacks require control of the SIM card itself, which could come through various means such as compromised SIM software, physical tampering, or supply chain vulnerabilities, the researchers suggest that retiring the RUN AT command and other risky functionalities could be the best long-term solution.
While modern smartphones seem to have largely mitigated these risks, the IoT world still needs to address the issue. The researchers disclosed their findings to Google, Oppo, Quectel, Semtech, and Qualcomm in March 2025, with Google patching the vulnerability in Android 13 through 16 in December 2025. The GSMA is also tracking the issue as CVE-2026-0122.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.