Loading…
Tuesday August 11, 2026 3:40pm - 4:00pm EDT
Tomasz Lisowski, University of Birmingham; Kristian Covic, Fuzzware; Marius Muench, University of Birmingham


Hostile SIMs have been discussed as an attack vector against Mobile Equipment (ME) connected to cellular networks. One main attack path are proactive commands sent from the SIM to the victim device. In this work, we examine the threats posed by the RUN AT command which are SIM-originating requests for the ME to execute a specified AT command, effectively creating a SIM AT interface.

To explore this interface, we introduce the CATana toolkit and use it to analyze real-world devices. Despite existing community knowledge on proactive commands and the dangers of AT commands, our investigation shows that SIM AT commands pose a significant security risk for MEs.

We survey 26 different MEs (8 IoT devices and 18 smartphones) and find that 9 expose the SIM AT interface, leading to the discovery of 4 vulnerabilities. We present case studies demonstrating the impact of discovered vulnerabilities, including command execution, arbitrary file read, downgrading connections to 2G, and Denial-of-Service (DoS) of the ME. Crucially, our work emphasizes the security benefit of hardening, deprecating, or disabling, the SIM AT interface.


https://www.usenix.org/conference/woot26/presentation/lisowski
Tuesday August 11, 2026 3:40pm - 4:00pm EDT
Harborside Ballroom B

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link