Can a Malicious SIM Card Hijack Your Cellular IoT Devices?

Article Highlights
Off On

The assumption that a Subscriber Identity Module is merely a passive vault for cryptographic keys and identity credentials has been fundamentally challenged by security findings that demonstrate how these tiny chips can serve as Trojan horses. For years, the security perimeter of cellular Internet of Things deployments focused almost exclusively on shielding against external network intrusions or unauthorized cloud access, yet recent revelations from the University of Birmingham and the cybersecurity firm Fuzzware indicate that the primary threat vector may already be inside the device. By exploiting standardized communication protocols that were designed for network management, a malicious SIM card can now seize total control over host hardware, turning seemingly benign components into active exploit platforms. This vulnerability allows for the execution of unauthorized code on sensitive infrastructure, such as electric vehicle charging stations and industrial routers, effectively bypassing several layers of modern security architecture. The discovery highlights a critical oversight in hardware design where the unconditional trust placed in the SIM card interface creates a direct pathway for attackers to manipulate the core functions of the device without needing remote network access.

The Technical Catalyst: Legacy Roots of Modem Control

At the heart of this security crisis is a mechanism known as the “RUN AT” proactive command, a specialized feature within the cellular standard that permits a SIM card to interact directly with the cellular module. While this interface was originally intended to facilitate legitimate maintenance tasks such as network configuration and diagnostics, researchers have found that it functions as an unauthenticated backdoor into the modem’s internal operations. Historically, cellular communication has relied on the AT (Attention) command set, a legacy language developed in the early 1980s that remains the foundational protocol for controlling modem hardware today. Because the “RUN AT” command grants the SIM the authority to issue these instructions unilaterally, a hostile card can transition from a simple data storage unit into a master controller capable of reconfiguring the device. This inherent design flaw exists because the protocol lacks the necessary authentication layers to verify whether the command being issued by the SIM is safe for the host system to execute.

The architectural configuration of modern machine-to-machine hardware significantly exacerbates the risk, as these devices often lack the robust isolation found in high-end consumer electronics. Unlike standard smartphones where the application processor and the cellular modem are strictly segregated, many IoT modules utilize a more integrated approach where the modem communicates with a lightweight version of Linux or Android. When a SIM card sends an AT command that the radio component does not recognize as a standard network instruction, the system frequently passes the string directly up to the main application processor for further interpretation. This behavior creates an expansive and largely unprotected attack surface, as the main operating system may possess proprietary AT commands that interact with critical system files, payment processing software, or sensor controls. Without modern security filtering or input validation, the hardware treats the malicious SIM as a trusted administrator, allowing it to bridge the gap between the cellular radio and the core logic of the entire machine.

Empirical Evidence: Testing and Attack Realities

Comprehensive testing involving twenty-six distinct cellular devices revealed a stark contrast in security posture between consumer-facing mobile phones and industrial-grade connectivity modules. High-end smartphones, such as the latest iterations of the iPhone and Google Pixel, demonstrated a strong resistance to unauthorized AT command injection, likely due to more sophisticated operating system protections and hardware-level isolation. However, the majority of industrial IoT modules tested, particularly those incorporating components from major suppliers like Quectel, were found to be completely vulnerable to this method of exploitation. Although Qualcomm processors were identified as a common hardware link among many of the compromised devices, the ultimate level of risk was determined by the specific firmware configurations and software customizations implemented by individual manufacturers. This disparity suggests that the vulnerability is not merely a hardware defect but a failure of the broader ecosystem to account for the potential of a malicious peripheral hijacking the primary host system.

The real-world implications of these findings were illustrated through a series of successful exploitation scenarios that targeted critical infrastructure and personal data security. In one particularly alarming demonstration, researchers achieved full remote code execution on a commercially available electric vehicle charger by exploiting the device’s failure to sanitize specific input characters within a shell call triggered by the SIM card. By inserting a specially crafted card, they were able to gain root access to the charger’s operating system, potentially allowing for the manipulation of power delivery or the theft of user payment data. Furthermore, additional tests confirmed that a malicious SIM could force a target device into a legacy 2G connection, which is notoriously insecure and facilitates easy eavesdropping on data transmissions. In some cases, the SIM card was even able to utilize built-in module functions to exfiltrate private system files via email, doing so entirely in the background without any visible indication to the user that a security breach had occurred.

Strategic Defense: Physical Access and Long-Term Remediation

Executing a SIM-based hijacking requires the physical placement of a hostile card within the target hardware’s slot, a task that is surprisingly simple given the deployment environments of most IoT systems. Many industrial sensors, smart meters, and connectivity hubs are located in public or remote areas where physical security is minimal, making them susceptible to manual card swapping or the addition of thin “shim” cards that sit between the original SIM and the reader. Beyond direct physical tampering, there is the lingering threat of supply chain compromises where malicious cards could be installed before the hardware ever reaches the final end user. Because these devices are often designed for “set and forget” operation, a compromised SIM could remain active for years without being detected, providing a persistent foothold for attackers within a secure network. This physical accessibility, combined with the lack of internal monitoring for SIM-to-modem communication, makes the “hostile card” scenario a highly effective method for compromising infrastructure that is otherwise shielded from internet-based attacks.

The discovery of the “RUN AT” vulnerability prompted a multi-faceted response from the global technology community, highlighting the urgent need for a shift in how cellular trust models were constructed. Qualcomm took the lead by deciding to disable the “RUN AT” interface by default in its product lines starting in 2026, ensuring that new generations of modem hardware would no longer be susceptible to this specific vector of attack. Meanwhile, fleet operators were advised to conduct thorough audits of their existing hardware inventories to identify vulnerable modules and apply any available firmware patches provided by manufacturers. For legacy systems that could not be easily updated, security teams looked toward implementing network-level monitoring to detect unusual data patterns or unauthorized protocol shifts, such as forced downgrades to 2G connectivity. The industry as a whole moved toward a more zero-trust approach regarding internal hardware peripherals, recognizing that no component should be granted unauthenticated access to the primary system processor. These steps were essential in mitigating a hidden risk that had existed within the cellular standard for decades.

Explore more

Is AI Creating a Knowledge Gap in Software Engineering?

The silent hum of automated code generation has fundamentally shifted the baseline of software development, where sophisticated systems now emerge from simple natural language prompts rather than grueling nights of manual logic. In the current landscape of 2026, the velocity of feature delivery has reached an unprecedented peak, yet this efficiency masks a growing fragility within the engineering workforce. We

AMD Eyes Trillion-Dollar Value as AI Boosts CPU Market

The rapid transformation of the global semiconductor landscape has reached a fever pitch as high-performance silicon emerges as the primary currency of a new digital economy. As the market searches for the next undisputed leader in the artificial intelligence revolution, Advanced Micro Devices has stepped into a bright spotlight, signaling its intent to join the exclusive ranks of trillion-dollar enterprises.

Is Data-Driven Content the New Authority in 2026?

The current digital marketplace has reached a point where a single verified statistic carries significantly more weight than a thousand pages of AI-generated prose or corporate conjecture. In this landscape, the sheer volume of information has fundamentally altered the value of subjective content, sparking a comprehensive shift in content marketing strategy. The industry is moving away from low-cost opinions toward

How Agentic AI Is Transforming Finance in Tech Companies

The realization that global technology leaders often maintain their internal financial systems with outdated spreadsheets while simultaneously selling cutting-edge artificial intelligence to the world has sparked a radical shift toward autonomous agentic architectures. This paradox, frequently referred to as the “Cobbler’s Children” syndrome, describes a reality where the very firms building the future of software are running their back offices

How Is Modern Technology Reshaping Global Talent Acquisition?

A tech startup in Denver recently filled its lead developer vacancy in under forty-eight hours by ignoring local resumes and hiring a specialist based in a quiet coastal village in Vietnam. This transaction, once a logistical nightmare that would have taken months of legal preparation, now occurs thousands of times a day across the planet. The traditional concept of a