Coming soon The Briev app is almost here. Leave your email and be first in on launch day.

Briev
Live
Technology

Malicious SIM cards can hijack phones, force 2G fallback and steal data

Researchers demonstrated that compromised SIM cards can issue AT commands to phones and IoT modems, causing shutdowns, data leaks, 2G downgrades and even code execution.

Security researchers from the University of Birmingham, together with Fuzzware, presented findings at the USENIX WOOT conference that malicious SIM cards can leverage the RUN AT command to issue low-level instructions to host devices. In trials covering 18 smartphones and eight IoT modems, nine devices exposed an AT command interface, with seven of the eight IoT modules doing so. Exploits demonstrated included forcing a handset to power down, killing its modem, forcing a fallback to insecure 2G networks, reading files, and executing code via a command-injection bug in a Quectel EC25-AFX module.

An Oppo Reno14 F 5G was found to support 198 AT commands, some of which could not be reversed by standard airplane-mode or SIM-disable actions. The researchers disclosed the vulnerabilities to vendors and the GSMA, prompting Qualcomm to ship a hardened configuration that disables the SIM AT interface by default, while the GSMA tracks the issue as CVD-2026-0122. Long-term mitigation may require retiring risky proactive SIM features altogether.

Why it matters

It reveals a hidden attack vector that could let attackers control phones and IoT devices, threatening privacy and network security.

In this story

malicious SIMAT command interface2G downgradecode executionIoT modemRUN ATsecurity researchCVE-2025-48618CVD-2026-0122