The Chonkerton

Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G

tech

Researchers have discovered that malicious SIM cards can compromise smartphones and connected devices in surprising ways. The Register reports they demonstrated attacks including shutting down phones, forcing them to drop from 5G to 2G, stealing files, and even executing code — all through so-called proactive SIM functionality, a feature built into cellular specifications that allows SIMs to issue commands to modems. Testing 26 devices, the team found nine exposed dangerous AT command interfaces to the SIM, with IoT modems particularly vulnerable: seven of eight tested modems were exposed. In one demonstration, they achieved code execution on an EV charger; in another, they forced an Oppo smartphone to downgrade to 2G, and the downgrade proved nearly impossible to reverse. The catch: exploiting these vulnerabilities requires control of the SIM itself — whether through compromised SIM software, physical tampering, or abuse by a malicious carrier. Qualcomm has released a hardened configuration disabling the SIM AT interface by default, and the industry is tracking the issue more broadly, but researchers say the real fix is retiring this risky SIM functionality altogether.

Source: https://www.theregister.com/security/2026/08/11/malicious...

Listen to this story

Hear this and more stories in a personalized audio briefing.

Open The Chonkerton