Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G

← Back to the feed

Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G

The Register · 2 hours ago

Researchers at the University of Birmingham and Fuzzware have shown that a malicious SIM card can hijack a phone or connected device by exploiting standardised "proactive SIM" features, potentially executing code, stealing files, forcing a shutdown, or downgrading a connection to 2G. Because the attack abuses functionality explicitly defined in cellular technical specifications rather than a coding flaw, it works against fully compliant devices, and the team argues that hostile SIMs remain largely absent from current threat models despite prior warnings.

Using a toolkit called CATANA, the researchers tested 26 devices, finding that 9 of them, including 7 of 8 IoT modems tested, exposed an AT command interface to the SIM. Demonstrated attacks included code execution on an Autel EV charger via a Quectel modem flaw, a persistent forced downgrade to 2G on an Oppo Reno14 F 5G that could not be undone through normal settings, and file theft from a Quectel EG25-G modem. They also found a related Android flaw (CVE-2025-48618), patched by Google in December 2025, that let a hostile SIM open a malicious webpage without user interaction. Exploitation requires control of the SIM itself, via compromised software, physical tampering, a malicious carrier or supply-chain compromise, and vendors including Google, Qualcomm and the GSMA have been notified, with Qualcomm already shipping a hardened default configuration.

  • Malicious SIMs can exploit standard features to attack phones
  • Attacks can force 2G downgrades, steal files, run code
  • Requires SIM control; some vendors already issuing fixes

Americas Business Markets Research Science World

Read the full article at the source →