Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G
Overview
Researchers from the University of Birmingham and Fuzzware have discovered a serious security flaw involving compromised SIM cards that can hijack smartphones and other cellular devices. These malicious SIMs can issue commands that allow attackers to steal sensitive information, disrupt communication, and even downgrade devices to the less secure 2G network. This vulnerability arises from a legitimate feature in the cellular specification known as Proactive SIM, which enables a SIM card to send commands to the device. This discovery raises significant concerns for users of affected devices, as it can lead to unauthorized access and data theft. The researchers stress the importance of addressing this issue to protect users from potential exploitation.
Key Takeaways
- Affected Systems: Smartphones and cellular-connected devices that use affected SIM cards.
- Action Required: Users should monitor for suspicious SIM card activity and consider replacing compromised SIMs.
- Timeline: Disclosed in October 2023
Original Article Summary
Researchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, disrupt communications, downgrade connections to 2G, and in some cases execute code. Tomasz Piotr Lisowski and Dr Marius Muench of the University of Birmingham, working with Kristian Covic from Fuzzware, traced this to a legitimate function already built into the cellular spec. That function is Proactive SIM. It lets a card send … More → The post Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G appeared first on Help Net Security.
Impact
Smartphones and cellular-connected devices that use affected SIM cards.
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Disclosed in October 2023
Remediation
Users should monitor for suspicious SIM card activity and consider replacing compromised SIMs. Mobile network operators should review their security measures related to SIM card functionality.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Vulnerability.