Malicious SIMs hijack phones, IoT modems via 'RUN AT' commands
TL;DR. Researchers uncovered how malicious SIM cards can exploit standard functionality to control phones and IoT modems. - The 'RUN AT' command allows SIMs to execute AT commands, leading to data leaks, connection downgrades, and code execution. - A toolkit called CATANA tested 26 devices, finding nine exposed AT command interfaces, especially in IoT modems. - Vulnerabilities allowed code execution on an Autel EV charger and full control over an Oppo Reno14 F 5G.
- Malicious SIM cards can leverage 'RUN AT' functionality to issue AT commands to devices.
- This allows for data exfiltration, denial of service (e.g., shutting down phones), downgrading connections to 2G, and even code execution.
- The vulnerabilities are 'specification-compliant,' meaning they exploit intended but abusable features in cellular communication standards.
- Researchers demonstrated these attacks on various smartphones and IoT modems, including an EV charger and an Oppo phone.
Sources
- Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G — theregister.com
- thehackernews.com — thehackernews.com