Researchers uncovered SIM card weaknesses that could let attackers remotely control connected devices, downgrade network security, open malicious links and disrupt equipment without interaction.

Fuzzware and cybersecurity researchers from the University of Birmingham used the CATana analysis toolkit to examine how malicious or compromised SIM cards can interact with connected devices. Their findings, presented at the 2026 USENIX WOOT Conference, reveal an overlooked attack surface affecting smartphones, IoT modules, EV chargers and industrial equipment.
The researchers tested 26 representative devices, including 18 consumer smartphones and eight cellular IoT modules embedded in connected cars and electric-vehicle charging stations. They found that SIM-originated commands could be processed by several devices through the SIM-to-modem interface.
The issue centres on a built-in capability known as “Proactive SIM”, which allows a SIM card to issue commands directly to a device’s modem. The researchers also examined AT commands, a legacy instruction system used to control cellular hardware.
According to the study, exploiting this interface could give an attacker extensive control without requiring user interaction. Demonstrated actions included executing arbitrary code, stealing sensitive hardware identifiers, forcing locked Android phones to open malicious links, downgrading connections from 4G to vulnerable 2G networks, and remotely disconnecting or shutting down devices.
The potential impact extends beyond smartphones. Industrial routers, EV chargers and automated vehicle systems can expose a SIM slot even when other external interfaces are heavily protected. Researchers warned that hostile SIM cards could reach devices through compromised software updates, rogue cellular operators or supply-chain tampering during manufacturing.
The team said affected chip manufacturers, device vendors and the GSMA began rolling out software updates and hardened configurations after the findings were disclosed privately.
The research highlights how SIM cards, often treated simply as subscriber-identification components, can function as powerful computing elements within connected systems. The researchers argue that SIM-related threats should receive greater attention in security models as cellular connectivity becomes increasingly embedded in critical infrastructure.


