Malicious SIM cards can hijack the modems inside EV chargers and industrial gear, researchers find

A team at the University of Birmingham showed that a booby-trapped SIM can run attacker code on the cellular modules baked into cars, routers and chargers.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge photoreal close-up of a server motherboard UEFI firmware chip under cool blue rack lighting, shallow depth of field, faint amber glow fr
Share

Key points

  • Researchers at the University of Birmingham and security firm Fuzzware tested 26 phones and cellular modules and found many will run commands sent by a malicious SIM card.
  • The flaw affects the modems built into electric-vehicle chargers, industrial routers, and car telematics units, not just handsets.
  • The attack abuses a decades-old feature called the SIM Application Toolkit, which lets the card tell the device what to do.
  • On stripped-down internet-connected devices, running attacker commands on the modem can hand over the whole unit.
  • The work was first reported by The Hacker News and is being tracked by researchers as a supply-chain risk for cellular IoT.

A SIM card is supposed to be a passive thing. You slide it into a phone, it proves who you are to the mobile network, and that is that.

It turns out the little chip can do rather more than that. And if the SIM is malicious, it can tell the device it sits in to run commands chosen by an attacker.

Researchers at the University of Birmingham, working with the security firm Fuzzware, tested 26 phones and cellular modules. They found the capability was widespread.

What exactly did the researchers find?

They found that a hostile SIM card can push commands into the modem, the small radio chip that handles the cellular connection, and get them executed. On a phone that is bad enough. On an industrial device with no screen and no user watching, it is worse.

The trick abuses a feature called the SIM Application Toolkit, a set of instructions defined in the mobile standards back in the 1990s so that carriers could push menus and prompts to handsets. That same channel, the researchers showed, can be pushed further than the designers intended.

Why does this matter beyond phones?

Because the same cellular modules sit inside things most people never think of as computers. Electric-vehicle chargers on the side of a car park. Industrial routers in factories and water plants. Telematics units bolted into cars that report location and diagnostics back to the manufacturer.

These devices are often built around an off-the-shelf cellular module from a handful of vendors. If the module can be taken over by the SIM inside it, the whole device can be taken over. There is no user to notice a strange prompt.

Detail What the research says
Devices tested 26 phones and cellular modules
Research team University of Birmingham and Fuzzware
Feature abused SIM Application Toolkit
Devices at risk EV chargers, industrial routers, car telematics

How would an attacker actually pull this off?

They would need to get a malicious SIM into the target device. That sounds like a high bar, and for a phone in your pocket it is. For a roadside EV charger or a fleet of trucks fitted with telematics boxes at a depot, physical access is a much softer problem.

There is also the supply chain to worry about. SIMs for industrial devices are often shipped in bulk, provisioned by third parties, and installed by contractors. Any point along that path is a chance to swap in a hostile card.

Who is behind this, and is it being exploited?

This is academic research, not an incident report. No known group is tracked as using the technique in the wild. The value of the work is that it shows the capability exists in shipping hardware, and that the mobile industry's assumption of a trusted SIM does not hold when the SIM is the attacker.

Expect vendors of cellular modules to push firmware updates that tighten what SIM Toolkit commands the modem will accept. Expect operators of large IoT fleets, utilities, car makers, logistics firms, to start asking harder questions about where their SIMs came from.

For ordinary phone users, there is nothing to do today. Do not accept a SIM card from a stranger. That was already good advice.

© 2026 Threat Vectr