Cyber Resilience
← All news
Corroborated

Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G

Our takeResearchers showed that a malicious SIM can hijack the modem on many phones, steal files, force a 2G downgrade, and in some cases run code. If you control your own cellular devices, audit SIM trust and firmware updates now.
Sources (2)
What this means for you — Security leader:Audit which devices in your fleet expose modem AT command interfaces to the SIM; disable unnecessary 2G fallback and monitor for unexpected connection downgrades or outbound file transfers.
What this means for you — Lean IT orgs:Check whether any of your phones, tablets or IoT devices can be reached by a malicious SIM; turn off 2G where possible and watch for sudden shutdowns or data theft.
What this means for you — MSP:For clients running cellular IoT, vehicles or remote devices, confirm SIM command interfaces are locked down, 2G fallback is minimized, and modem logs are reviewed for anomalous commands.
What this means for you — Researcher:Examine your lab devices and test setups for exposure to SIM-originated AT commands; the attack surface extends beyond phones to any cellular modem.