A study at the USENIX WOOT conference uncovers how compromised SIMs can send malicious AT commands, risking smartphones, EV chargers, and more, despite decades-old commands still being active in modern systems.
Researchers at the University of Birmingham have shown that a compromised SIM card can do far more than place calls or connect a handset to a network. At this week’s USENIX WOOT conference in Baltimore, the team said a SIM feature known as Proactive SIM can be abused to send AT commands directly to a device modem, creating a path into smartphones, electric vehicle chargers and other connected equipment. The commands themselves have existed since the 1980s, but the study suggests they remain a live security risk in modern cellular systems.
Working with Fuzzware security researchers Tomasz Piotr Lisowski and Kristian Covic, the team built a toolkit called CATana to test SIM-originated AT commands across 26 devices, including 18 smartphones and eight internet-connected modules used in chargers, industrial systems and vehicles. According to the conference paper, nine of those devices exposed the SIM AT interface, and the researchers used that access to identify multiple weaknesses, including command execution and denial-of-service conditions.
The reported impacts were broad. In some cases, the researchers said a hostile SIM could re-enable debug interfaces, reveal sensitive identifiers, send messages, force a device onto weaker 2G service, shut it down or cut off communications entirely. On recent Android phones, they also found that a malicious SIM could trigger a locked handset to open an attacker-controlled website without any user action. Dr Marius Muench said the relevant behaviour is already described in cellular specifications, making the attacks “specification-compliant”.
The team said four main threat scenarios stood out: remote compromise of SIM software, physical substitution of a SIM, abuse of remote SIM management by a compromised operator, and tampering during manufacture or distribution. Their findings have been reported to the GSM Association and affected manufacturers, and the researchers said updates and hardened configurations have already been issued in some cases. The issues are tracked under CVE-2025-48618, CVE-2026-57550 and CVE-2026-0122, while earlier USENIX work by the same group showed how hostile SIMs can be used to probe mobile basebands and related attack surfaces.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





