'The attacks we found only scratch the surface of what is possible': Experts say so-called 'Proactive SIM' cards can hijack smartphones, Io T devices and even EV chargers | Tech Radar
Overview
News, deals, reviews, guides and more on the newest computing gadgets
Start exploring exclusive deals, expert advice and more
Details
Unlock and manage exclusive Techradar member rewards.
Unlock instant access to exclusive member features.
Get full access to premium articles, exclusive features and a growing list of member rewards.
'The attacks we found only scratch the surface of what is possible': Experts say so-called 'Proactive SIM' cards can hijack smartphones, Io T devices and even EV chargers
Standardized SIM command from the modem era lets a hostile card run code inside an EV charger
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
Researchers find a standardized SIM command is exposed on nine of 26 tested devices and used it to achieve code execution on a commercial EV charger
The exposure is concentrated in machine-to-machine hardware rather than phones, affecting six of eight cellular modules but only three of 18 handsets, with no i Phone or Pixel among them
Every attack requires the attacker to already control the SIM, and while Qualcomm has produced a hardened configuration disabling the interface by default, no vendor had published a public advisory yet
A malicious SIM card can instruct the device it sits in to run commands of an attacker's choosing, and on the cellular modules embedded in electric vehicle chargers, industrial routers, and car telematics units, essentially allowing it to take the entire device over.
Researchers from the University of Birmingham and the German security firm Fuzzware demonstrated this against a commercial Autel EV charger, achieving code execution driven entirely SIM card-issued commands.
The work focuses on a standardized feature called Proactive SIM, which as a feature, is not malicious; it's a standard in a cellular specification that lets a SIM push commands to a device rather than acting as a passive identifier for one's identity on a network.
The problem is one specific command in that set, RUN AT, which asks the modem to execute an AT command, the modem control language dating to the 1981 Hayes Smartmodem that every vendor has since extended with its own additions.
The support extender essentially gives a SIM module its own general-purpose console on devices that lack safeguards to prevent such an attack.
Android users targeted by new Wind Relay malware which can clone contactless cards in just 13 minutes
Experts warn 2.2 million cars could be at risk of hijacking via Bluetooth
Security experts warn Claude Code can be exploited simply by trying to be helpful
Tomasz Piotr Lisowski and Dr Marius Muench of Birmingham, working with Fuzzware's Kristian Covic, built a toolkit called CATana to find out what a hostile card could do with that console.
The team tested 26 devices, 18 smartphones and eight cellular modules, and found the SIM AT interface exposed on nine of them. The exposure is overwhelmingly concentrated in machine-to-machine hardware: six of the eight modules accepted the command, compared with just three of the 18 phones: the Oppo Find X5, the Oppo Reno 14 F 5G, and the Asus Zenfone 9. This makes it not exactly a Simjacker-esque exploit but still one that needs to be taken seriously.
All nine devices that accepted the command run a Qualcomm chip or modem, but five others that do were not vulnerable to the attack. The researchers first shared the reports with Google, Oppo, Quectel, Semtech, and Qualcomm in March 2026, and with the GSMA in May. Qualcomm has since built a hardened configuration that switches the interface off by default, which the researchers say will be the default on future devices.
The attack vector, however, is limited because, to leverage it, the attacker must already control the SIM itself. Knowing a victim's contact number is not enough; the attacker needs physical access to the SIM slot. The exploit is real and concerning, but it has limited utility compared to a remote one for smartphones.
The Io T side is more concerning, however: unattended equipment with an accessible SIM tray can now potentially be exploited, and physical swaps might be easier than with something more personal, like one's personal phone. The card essentially talks to the equivalent of a Linux computer, one that the paper calls a rich attack surface for hostile SIM cards.
For now, the irony is that while modern smartphones have largely retired the surface this attack vector exploits, the machine-to-machine world has not, and the equipment least likely to receive a firmware update is the equipment most exposed currently.
Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.
You must confirm your public display name before commenting
North Face everyday backpacks are up to 33% off at Amazon — just in time for back to school season
'This technology turns every router into a potential means for surveillance': Report claims Wi-Fi devices could 'quietly identify' people with nearly 100% accuracy
The i Pad Air M4 hits its biggest discount yet since Apple's recent price hikes — save $100 at Amazon
Cherokee Nation joins list of tribes banning data centers on tribal lands due to water, energy, noise, and cultural resource protection concerns — and all new projects require ‘early consultation’
I tried Chat GPT's new interactive quizzes on 5 subjects I thought I knew well — it quickly found the gaps in my knowledge
Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.
© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.
Key Takeaways
- News, deals, reviews, guides and more on the newest computing gadgets
- Start exploring exclusive deals, expert advice and more
- Unlock and manage exclusive Techradar member rewards
- Unlock instant access to exclusive member features
- Get full access to premium articles, exclusive features and a growing list of member rewards



