Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G
PoC publicAndroidOur summary
University of Birmingham researchers demonstrated that compromised SIM cards can leverage the Proactive SIM feature to execute arbitrary AT commands on compatible modems, potentially leading to code execution, data theft, or forced network downgrades. Testing revealed vulnerabilities in devices from Qualcomm, Quectel, OPPO, Autel, and ASUS, including a command injection flaw in an AUTEL EV charger using a Quectel module.
The study also identified CVE-2025-48618, which allowed hostile SIMs to launch browser sessions on locked Android phones without user interaction; Google fixed this issue in Android 13 through 16. The team has published a toolkit called CATana and recommends retiring the RUN AT command entirely rather than just patching specific instances, as the underlying specification still permits significant risk.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.