SendTech Times
News
MARKET SIGNAL:

Hostile SIM Research Exposes Phones And EV Chargers To Command Attacks

Newsroom brief

University of Birmingham and Fuzzware researchers used CATana to show how malicious SIM cards can issue modem commands against phones, EV chargers and industrial equipment.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: Interesting Engineering
Hostile SIM Research Exposes Phones And EV Chargers To Command Attacks

The University of Birmingham and Fuzzware's 26-device CATana test turned the SIM slot into a live risk surface for phones, electric-vehicle chargers and industrial equipment.

Interesting Engineering detailed research presented at the 2026 USENIX WOOT Conference by the University of Birmingham and Fuzzware, where a custom toolkit called CATana examined how malicious or compromised SIM cards can use standards-compliant commands against cellular devices.

SIM Cards Became A Command Channel

The issue sits in a feature rather than a conventional software bug.

Proactive SIM functions allow a Subscriber Identity Module to send instructions to a device modem, and legacy AT commands give that channel access to cellular hardware controls that many security models treat as trusted.

The CATana work covered 26 representative devices, including 18 consumer smartphones and eight cellular IoT modules used in connected cars, EV chargers and industrial equipment.

Several devices processed SIM-originated AT commands, creating a path for attacks that do not require a user to click a link or approve a prompt.

Marius Muench, an assistant professor in computer science at the University of Birmingham, framed the risk as a standards problem: the SIM's proactive capabilities and the resulting attack surface are explicitly defined in cellular specifications, making some attacks compliant with the rules devices are built to follow.

Device Takeover Risks Extend Beyond Phones

The tested attack paths included arbitrary code execution, theft of sensitive hardware identifiers, forced opening of malicious links on locked Android phones, downgrades from 4G to less secure 2G networks, and remote disconnection or shutdown of devices.

That range makes the SIM interface more than a privacy issue; it can affect service availability and equipment control.

EV chargers and industrial routers are particularly exposed because their external ports and software entry points are often locked down while the SIM slot remains a normal connectivity component.

A hostile SIM could arrive through a physical swap, a compromised SIM software update, rogue operator access to remote management systems or supply-chain tampering during manufacturing.

Kristian Covic of Fuzzware called hostile SIMs an overlooked attack vector.

After responsible disclosure to chipmakers, device vendors and the GSMA, some parties began issuing software updates and hardened configurations designed to neutralize rogue AT commands.

Patch Coverage Is Now The Operational Question

The disclosure creates a practical burden for manufacturers, network operators and infrastructure owners: SIM behaviour has to be part of the threat model for any cellular device that controls critical or revenue-generating equipment.

Phones can receive updates at large scale, but embedded modules in chargers, vehicles and industrial systems may have slower maintenance cycles and longer field lives.

The unresolved evidence gap is patch reach: the material did not show whether hardened configurations have reached deployed fleets.

Near-term risk now depends on vendor response speed, operator SIM-management controls and whether infrastructure owners can inventory cellular modules before attackers treat the SIM slot as a trusted backdoor.

Share this article
inXf

Related articles

More
Target-Locked Malware Narrows Central Asia Cyber Espionage Risk
Cybersecurity

Target-Locked Malware Narrows Central Asia Cyber Espionage Risk

Backend News reported, citing Kaspersky, that a campaign active since January 2025 used custom malware, OctLurk and SilkLurk backdoors, and PlugX to target public-sector, healthcare and research bodies in Central Asia and Syria.

FTP Banner Dead Drops Deliver E4del And PINHOLE RAT Commands
Cybersecurity

FTP Banner Dead Drops Deliver E4del And PINHOLE RAT Commands

Two newly documented RATs, E4del and PINHOLE, use FTP server banners as dead-drop command sources, with SOCRadar tracing chains that involve WebDAV, PowerShell, Cloudflare Workers and injection techniques.

Kratos Takedown Leaves Microsoft 365 Session-Theft Risk Unfinished
Cybersecurity

Kratos Takedown Leaves Microsoft 365 Session-Theft Risk Unfinished

German and US law enforcement took more than 200 Kratos phishing-kit servers offline, but investigators still tie the service to roughly 1,800 customers and session-theft attacks against Microsoft 365.

Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery Chain
Cybersecurity

Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery Chain

DeveloperTech's article on Arctic Wolf Labs research describes a fake-repository campaign that used polished GitHub project pages as a delivery route for BoryptGrab malware. The case makes artifact provenance and workstation controls more important than visual trust in repository pages.

Calix Router Flaw Exposes Home Devices To Public Internet
Cybersecurity

Calix Router Flaw Exposes Home Devices To Public Internet

An unpatched Calix GS7 XGS router flaw lets unauthenticated attackers create port-forwarding rules that can expose devices inside broadband customers' home networks.

Motorola GrapheneOS Plan Makes Privacy Android A Premium-Phone Bet
Cybersecurity

Motorola GrapheneOS Plan Makes Privacy Android A Premium-Phone Bet

Ars Technica reported that Motorola-supported GrapheneOS phones are on track for 2027, with pricing expected above Pixel devices because the privacy-focused Android system depends on high-end security hardware.

macOS Screen Sharing Flaw Gets Critical Rating After Root Compromises
Cybersecurity

macOS Screen Sharing Flaw Gets Critical Rating After Root Compromises

CVE-2026-65400 in macOS Screen Sharing was raised to a 9.8 critical score after Dutch officials documented exposed Macs being rooted and used for Monero mining.

Threema DDoS Attacks Expose Hosted Messaging Availability Gap
Cybersecurity

Threema DDoS Attacks Expose Hosted Messaging Availability Gap

Large DDoS attacks disrupted Threema’s hosted messaging service while On-Prem customers avoided the outage, prompting the company to add upstream DDoS filtering.

Keep Reading

More Stories

Latest
Philippines DICT Chief Stays At Work Amid Resignation ReportCapital & PolicyOct 7, 2026Philippines DICT Chief Stays At Work Amid Resignation ReportDICT Secretary Henry Aguda said he remains focused on the department’s work after a report claimed he had resigned or been forced to resign, while platform-safety and public Wi-Fi issues remain active.Singapore Online Shoppers Rank Lowest For Savvy Buying In Southeast AsiaFintech & Digital PaymentsOct 7, 2026Singapore Online Shoppers Rank Lowest For Savvy Buying In Southeast AsiaA Cube-Lazada study covered by Asian Business Review found only 9% of Singapore online shoppers qualify as savvy, with marketplace exposure and purchase protection among the main gaps.Saudi World Cup Contractor Hack Exposes 1.5 Million Files, Cyber Group SaysCybersecurityOct 7, 2026Saudi World Cup Contractor Hack Exposes 1.5 Million Files, Cyber Group SaysA cyber monitor identified a breach at a Saudi construction consortium linked to Jeddah Central Stadium, with about 17 terabytes of project and employee data reportedly stolen.Hamilton County Schools Starts K-12 Quantum Curriculum With TN QuantumWorksSportsOct 7, 2026Hamilton County Schools Starts K-12 Quantum Curriculum With TN QuantumWorksHamilton County Schools is using TN QuantumWorks curriculum from Chattanooga Quantum Collaborative and Thinking Media to introduce quantum concepts across grade levels as EPB adds a $22 million quantum computer.SUBCO Weighs Australia Cable Ship As Repair Capacity Shifts Toward 2030PoliticsOct 7, 2026SUBCO Weighs Australia Cable Ship As Repair Capacity Shifts Toward 2030SUBCO is considering an uncrewed survey vessel and a US$165 million cable-laying ship as Australia looks for more certain submarine cable survey and repair capacity beyond 2030.Nettle Raises $4.8 Million To Expand AI Insurance InspectionsReal EstateOct 7, 2026Nettle Raises $4.8 Million To Expand AI Insurance InspectionsIrish-founded Nettle raised a $4.8 million seed round led by MTech Capital to expand its AI insurance inspection platform across the US and Europe.Alliance Backs Kenya’s Cloud9 With $500,000 for Cross-Border PaymentsCapital & PolicyOct 7, 2026Alliance Backs Kenya’s Cloud9 With $500,000 for Cross-Border PaymentsAlliance invested $500,000 in Kenyan fintech Cloud9 as the company expands from digital banking into cross-border payments, stablecoin settlement and business accounts after two acquisitions.Googlebook Launch Leaves Samsung Phones Waiting For Better Together SupportDevices & Consumer TechOct 7, 2026Googlebook Launch Leaves Samsung Phones Waiting For Better Together SupportGooglebook laptops launched with Better Together phone features limited to Pixel devices, while Google says Samsung support for Android 17 phones will arrive in the coming weeks.AstaBrief Gives Asta An Open 8B Fast Mode For Scientific ReportsCapital & PolicyOct 7, 2026AstaBrief Gives Asta An Open 8B Fast Mode For Scientific ReportsAi2 released AstaBrief 8B as an open-weights report-generation model for Asta, with a one-pass pipeline that averaged 51.1 seconds per report in Fast mode.Atlassian Warns Data Centre Admins To Patch Critical File Access FlawCybersecurityOct 7, 2026Atlassian Warns Data Centre Admins To Patch Critical File Access FlawAtlassian is urging Data Centre customers to patch CVE-2026-21589, a critical flaw that can let unauthenticated attackers read specific web-root files.Finland Halts Work at Two Google Data-Centre SitesEconomyOct 7, 2026Finland Halts Work at Two Google Data-Centre SitesFinland’s environmental supervisor ordered preparatory work to stop at Google-linked data-centre sites in Muhos and Kajaani while Tuike Finland answers questions over forest clearance and environmental assessment requirements.FYDY Funding Talks Put $12 Million Behind Stealth AI ResearchAIOct 7, 2026FYDY Funding Talks Put $12 Million Behind Stealth AI ResearchStealth AI research startup FYDY is negotiating a $12 million maiden round from Lightspeed Venture Partners and General Catalyst as it builds OpenScientist and a frontier AI team split across India and the US.