This post is also available in:
SIM cards are normally treated as trusted components whose main job is to connect a device to a cellular network. New security research shows why that assumption can be dangerous. If a SIM or eSIM is compromised, it may be able to issue commands directly to the device’s modem, potentially interfering with communications, exposing information or opening a path for deeper attacks.
Researchers from the University of Birmingham and Fuzzware investigated this overlooked attack surface using a new toolkit called CATana. Their work, presented at the 2026 USENIX WOOT Conference, examined a cellular feature known as Proactive SIM, which allows SIM cards to initiate certain actions on connected devices.
The key issue involves AT commands, instructions originally developed to configure and control modems. Cellular specifications allow a SIM to request that some of these commands be executed. That functionality was designed around the assumption that the SIM itself could be trusted. The toolkit allowed the researchers to test what happens when it cannot.
The team examined 26 devices, including 18 smartphones and eight cellular IoT modules of the type used in electric vehicle chargers, industrial equipment and connected vehicles. Several accepted AT commands originating from the SIM, creating an interface that could be abused by a malicious card.
Depending on the device, the researchers demonstrated capabilities including reopening disabled debugging interfaces, extracting device identifiers, sending messages, initiating calls and disabling cellular connectivity. According to TechXplore, they also found ways to force devices from 4G onto less secure 2G networks and, in one case, achieve arbitrary command execution on the communications processor.
The problem extends beyond physical SIM cards. The researchers outlined several ways a SIM or eSIM could become hostile, including remote exploitation of SIM software, physical replacement or hardware implants, abuse of remote management capabilities by a compromised operator, and manipulation during manufacturing or distribution.
IoT equipment may face particular risks because industrial devices, routers and vehicle systems are often intentionally designed with few externally accessible interfaces. A trusted SIM connection could therefore become an unexpected route around those restrictions. The researchers also found that on recent Android devices, a malicious SIM could force a locked phone to open an attacker-controlled website without user interaction.
The findings have clear implications for defense and critical infrastructure. Cellular connectivity is increasingly embedded in vehicles, communications equipment, industrial systems and remote infrastructure. A compromised SIM could provide attackers with an unconventional foothold that may be overlooked by security teams concentrating on conventional network interfaces.
The researchers disclosed their findings to the GSMA and affected manufacturers, and several vendors have since released software updates and hardened configurations. The vulnerabilities are tracked under CVE-2025-48618, CVE-2026-57550 and CVD-2026-0122.
The research highlights a broader security problem: components that have been trusted for decades can become attack surfaces when their original assumptions no longer match today’s threat environment.

























