Can a Malicious SIM Card Hijack Your Cellular IoT Devices?

Article Highlights
Off On

The assumption that a Subscriber Identity Module is merely a passive vault for cryptographic keys and identity credentials has been fundamentally challenged by security findings that demonstrate how these tiny chips can serve as Trojan horses. For years, the security perimeter of cellular Internet of Things deployments focused almost exclusively on shielding against external network intrusions or unauthorized cloud access, yet recent revelations from the University of Birmingham and the cybersecurity firm Fuzzware indicate that the primary threat vector may already be inside the device. By exploiting standardized communication protocols that were designed for network management, a malicious SIM card can now seize total control over host hardware, turning seemingly benign components into active exploit platforms. This vulnerability allows for the execution of unauthorized code on sensitive infrastructure, such as electric vehicle charging stations and industrial routers, effectively bypassing several layers of modern security architecture. The discovery highlights a critical oversight in hardware design where the unconditional trust placed in the SIM card interface creates a direct pathway for attackers to manipulate the core functions of the device without needing remote network access.

The Technical Catalyst: Legacy Roots of Modem Control

At the heart of this security crisis is a mechanism known as the “RUN AT” proactive command, a specialized feature within the cellular standard that permits a SIM card to interact directly with the cellular module. While this interface was originally intended to facilitate legitimate maintenance tasks such as network configuration and diagnostics, researchers have found that it functions as an unauthenticated backdoor into the modem’s internal operations. Historically, cellular communication has relied on the AT (Attention) command set, a legacy language developed in the early 1980s that remains the foundational protocol for controlling modem hardware today. Because the “RUN AT” command grants the SIM the authority to issue these instructions unilaterally, a hostile card can transition from a simple data storage unit into a master controller capable of reconfiguring the device. This inherent design flaw exists because the protocol lacks the necessary authentication layers to verify whether the command being issued by the SIM is safe for the host system to execute.

The architectural configuration of modern machine-to-machine hardware significantly exacerbates the risk, as these devices often lack the robust isolation found in high-end consumer electronics. Unlike standard smartphones where the application processor and the cellular modem are strictly segregated, many IoT modules utilize a more integrated approach where the modem communicates with a lightweight version of Linux or Android. When a SIM card sends an AT command that the radio component does not recognize as a standard network instruction, the system frequently passes the string directly up to the main application processor for further interpretation. This behavior creates an expansive and largely unprotected attack surface, as the main operating system may possess proprietary AT commands that interact with critical system files, payment processing software, or sensor controls. Without modern security filtering or input validation, the hardware treats the malicious SIM as a trusted administrator, allowing it to bridge the gap between the cellular radio and the core logic of the entire machine.

Empirical Evidence: Testing and Attack Realities

Comprehensive testing involving twenty-six distinct cellular devices revealed a stark contrast in security posture between consumer-facing mobile phones and industrial-grade connectivity modules. High-end smartphones, such as the latest iterations of the iPhone and Google Pixel, demonstrated a strong resistance to unauthorized AT command injection, likely due to more sophisticated operating system protections and hardware-level isolation. However, the majority of industrial IoT modules tested, particularly those incorporating components from major suppliers like Quectel, were found to be completely vulnerable to this method of exploitation. Although Qualcomm processors were identified as a common hardware link among many of the compromised devices, the ultimate level of risk was determined by the specific firmware configurations and software customizations implemented by individual manufacturers. This disparity suggests that the vulnerability is not merely a hardware defect but a failure of the broader ecosystem to account for the potential of a malicious peripheral hijacking the primary host system.

The real-world implications of these findings were illustrated through a series of successful exploitation scenarios that targeted critical infrastructure and personal data security. In one particularly alarming demonstration, researchers achieved full remote code execution on a commercially available electric vehicle charger by exploiting the device’s failure to sanitize specific input characters within a shell call triggered by the SIM card. By inserting a specially crafted card, they were able to gain root access to the charger’s operating system, potentially allowing for the manipulation of power delivery or the theft of user payment data. Furthermore, additional tests confirmed that a malicious SIM could force a target device into a legacy 2G connection, which is notoriously insecure and facilitates easy eavesdropping on data transmissions. In some cases, the SIM card was even able to utilize built-in module functions to exfiltrate private system files via email, doing so entirely in the background without any visible indication to the user that a security breach had occurred.

Strategic Defense: Physical Access and Long-Term Remediation

Executing a SIM-based hijacking requires the physical placement of a hostile card within the target hardware’s slot, a task that is surprisingly simple given the deployment environments of most IoT systems. Many industrial sensors, smart meters, and connectivity hubs are located in public or remote areas where physical security is minimal, making them susceptible to manual card swapping or the addition of thin “shim” cards that sit between the original SIM and the reader. Beyond direct physical tampering, there is the lingering threat of supply chain compromises where malicious cards could be installed before the hardware ever reaches the final end user. Because these devices are often designed for “set and forget” operation, a compromised SIM could remain active for years without being detected, providing a persistent foothold for attackers within a secure network. This physical accessibility, combined with the lack of internal monitoring for SIM-to-modem communication, makes the “hostile card” scenario a highly effective method for compromising infrastructure that is otherwise shielded from internet-based attacks.

The discovery of the “RUN AT” vulnerability prompted a multi-faceted response from the global technology community, highlighting the urgent need for a shift in how cellular trust models were constructed. Qualcomm took the lead by deciding to disable the “RUN AT” interface by default in its product lines starting in 2026, ensuring that new generations of modem hardware would no longer be susceptible to this specific vector of attack. Meanwhile, fleet operators were advised to conduct thorough audits of their existing hardware inventories to identify vulnerable modules and apply any available firmware patches provided by manufacturers. For legacy systems that could not be easily updated, security teams looked toward implementing network-level monitoring to detect unusual data patterns or unauthorized protocol shifts, such as forced downgrades to 2G connectivity. The industry as a whole moved toward a more zero-trust approach regarding internal hardware peripherals, recognizing that no component should be granted unauthenticated access to the primary system processor. These steps were essential in mitigating a hidden risk that had existed within the cellular standard for decades.

Explore more

Google Pixel 11 Pro XL Leak Reveals New Tensor G6 Specs

The mobile industry landscape faces a significant shift as leaked technical specifications for the upcoming Google Pixel 11 Pro XL suggest a radical departure from traditional silicon partnerships. This year, the focus centers on the Tensor G6 chip, which represents a pivotal milestone in the quest for hardware autonomy and specialized artificial intelligence processing. While previous iterations relied heavily on

Digital HR Technology – Review

The pervasive integration of artificial intelligence and machine learning into the modern global workforce has fundamentally transformed the traditional human resources department from a mere administrative back-office into a sophisticated engine of data-driven strategic planning. This metamorphosis is not merely a matter of convenience or modern aesthetic; it represents a tectonic shift in how organizations perceive the relationship between labor

Savvy Wealth Adds Blue Barn and Paragon to Reach $8 Billion

The financial services landscape is undergoing a massive transformation as technology bridges the gap between boutique personalized service and institutional-grade scale. Savvy Wealth has emerged as a primary architect of this shift, recently doubling its assets under management to reach a staggering $8 billion milestone. This expansion is defined by a $4 billion surge within the current year, a feat

Is Your Brand Just Automating or Truly Orchestrating?

Digital communication platforms currently possess the power to reach billions in milliseconds, yet this technological prowess often results in brands shouting through digital megaphones while customers desperately seek a single moment of genuine relevance. The modern consumer landscape is no longer satisfied with generic interactions that merely use a first name in an email subject line. Instead, there is a

What Is the New Math of E-Commerce Parcel Economics?

A standard procurement negotiation once focused on the simple lever of volume-based discounts to ensure profitability, but the modern landscape of e-commerce has rendered that linear equation dangerously incomplete. As of 2026, the retail sector is witnessing a profound shift where the traditional metrics of success—negotiated carrier rates and total package counts—no longer tell the full story of a company’s