Hostile SIM Research Exposes Phones And EV Chargers To Command Attacks
University of Birmingham and Fuzzware researchers used CATana to show how malicious SIM cards can issue modem commands against phones, EV chargers and industrial equipment.

The University of Birmingham and Fuzzware's 26-device CATana test turned the SIM slot into a live risk surface for phones, electric-vehicle chargers and industrial equipment.
Interesting Engineering detailed research presented at the 2026 USENIX WOOT Conference by the University of Birmingham and Fuzzware, where a custom toolkit called CATana examined how malicious or compromised SIM cards can use standards-compliant commands against cellular devices.
SIM Cards Became A Command Channel
The issue sits in a feature rather than a conventional software bug.
Proactive SIM functions allow a Subscriber Identity Module to send instructions to a device modem, and legacy AT commands give that channel access to cellular hardware controls that many security models treat as trusted.
The CATana work covered 26 representative devices, including 18 consumer smartphones and eight cellular IoT modules used in connected cars, EV chargers and industrial equipment.
Several devices processed SIM-originated AT commands, creating a path for attacks that do not require a user to click a link or approve a prompt.
Marius Muench, an assistant professor in computer science at the University of Birmingham, framed the risk as a standards problem: the SIM's proactive capabilities and the resulting attack surface are explicitly defined in cellular specifications, making some attacks compliant with the rules devices are built to follow.
Device Takeover Risks Extend Beyond Phones
The tested attack paths included arbitrary code execution, theft of sensitive hardware identifiers, forced opening of malicious links on locked Android phones, downgrades from 4G to less secure 2G networks, and remote disconnection or shutdown of devices.
That range makes the SIM interface more than a privacy issue; it can affect service availability and equipment control.
EV chargers and industrial routers are particularly exposed because their external ports and software entry points are often locked down while the SIM slot remains a normal connectivity component.
A hostile SIM could arrive through a physical swap, a compromised SIM software update, rogue operator access to remote management systems or supply-chain tampering during manufacturing.
Kristian Covic of Fuzzware called hostile SIMs an overlooked attack vector.
After responsible disclosure to chipmakers, device vendors and the GSMA, some parties began issuing software updates and hardened configurations designed to neutralize rogue AT commands.
Patch Coverage Is Now The Operational Question
The disclosure creates a practical burden for manufacturers, network operators and infrastructure owners: SIM behaviour has to be part of the threat model for any cellular device that controls critical or revenue-generating equipment.
Phones can receive updates at large scale, but embedded modules in chargers, vehicles and industrial systems may have slower maintenance cycles and longer field lives.
The unresolved evidence gap is patch reach: the material did not show whether hardened configurations have reached deployed fleets.
Near-term risk now depends on vendor response speed, operator SIM-management controls and whether infrastructure owners can inventory cellular modules before attackers treat the SIM slot as a trusted backdoor.




















