AI Signal 445
Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G
Standards-defined SIM functionality can be weaponized to execute code, exfiltrate files, force 2G fallback, and remotely disable devices.
Engineers building or operating cellular-connected devices must now treat the SIM as an untrusted input. Any device that exposes AT commands to the SIM is effectively running a second, unauthenticated control plane. The attacks are specification-compliant, so patching individual bugs will not close the entire surface.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
A malicious SIM can issue AT commands to the host modem, enabling code execution, file theft, and forced 2G fallback.
Nine of 26 tested devices exposed the AT interface to the SIM; IoT modems were far more likely to be vulnerable than smartphones.
The GSMA is tracking the issue, but the only long-term fix is to deprecate the RUN AT capability in the cellular standards.
THE CLUSTER