Overview
- Researchers from the University of Birmingham and Fuzzware built a toolkit called CATana and tested 26 representative devices, finding that several smartphones and most cellular IoT modules accepted SIM‑originated AT commands.
- The danger comes from the Proactive SIM RUN AT feature in cellular specifications, which lets a SIM request the modem execute AT commands that can control or reconfigure the radio hardware.
- The team demonstrated concrete exploits including silent code execution on modules, theft of device identifiers, forcing locked phones to open attacker websites, downgrading connections to 2G, and remotely disabling devices.
- Realistic attacker paths include exploiting SIM software, physically replacing or implanting SIMs, compromised mobile operators abusing remote SIM management, and supply‑chain tampering, making hostile SIMs plausible for phones, EV chargers, routers, and vehicle systems.
- The researchers disclosed findings to GSMA and vendors, three advisories and CVE/CVD entries were opened, and some manufacturers issued patches and hardened settings, but many deployed devices still need coordinated vendor, operator, and standards changes to remove the risk.