'The attacks we found only scratch the surface of what is possible': Experts say so-called 'Proactive SIM' cards can hijack smartphones, IoT devices and even EV chargers
Researchers find a standardized SIM command is exposed on nine of 26 tested devices and used it to achieve code execution on a commercial EV charger The exposure is concentrated in machine-to-machine hardware rather than phones, affecting six of eight cellular modules but only three of 18 handsets, with no iPhone or Pixel among them Every attack requires the attacker to already control the SIM, and while Qualcomm has produced a hardened configuration disabling the interface by default, no vendor had published a public advisory yet A malicious SIM card can instruct the device it sits in to run commands of an attacker's choosing, and on the cellular modules embedded in electric vehicle chargers, industrial routers, and car telematics units, essentially allowing it to take the entire device over.
Researchers from the University of Birmingham and the German security firm Fuzzware demonstrated this against a commercial Autel EV charger, achieving code execution driven entirely SIM card-issued commands.
One malicious SIM card to rule them all? The work focuses on a standardized feature called Proactive SIM, which as a feature, is not malicious; it's a standard in a cellular specification that lets a SIM push commands to a device rather than acting as a passive identifier for one's identity on a network.
The problem is one specific command in that set, RUN AT, which asks the modem to execute an AT command, the modem control language dating to the 1981 Hayes Smartmodem that every vendor has since extended with its own additions.
The support extender essentially gives a SIM module its own general-purpose console on devices that lack safeguards to prevent such an attack.
Tomasz Piotr Lisowski and Dr Marius Muench of Birmingham, working with Fuzzware's Kristian Covic, built a toolkit called CATana to find out what a hostile card could do with that console.
The team tested 26 devices , 18 smartphones and eight cellular modules, and found the SIM AT interface exposed on nine of them.
The exposure is overwhelmingly concentrated in machine-to-machine hardware: six of the eight modules accepted the command, compared with just three of the 18 phones: the Oppo Find X5, the Oppo Reno 14 F 5G, and the Asus Zenfone 9.
This makes it not exactly a Simjacker-esque exploit but still one that needs to be taken seriously.
All nine devices that accepted the command run a Qualcomm chip or modem, but five others that do were not vulnerable to the attack.
The researchers first shared the reports with Google, Oppo, Quectel, Semtech, and Qualcomm in March 2026, and with the GSMA in May.
Qualcomm has since built a hardened configuration that switches the interface off by default, which the researchers say will be the default on future devices.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.