hacker-news · Crawled Aug 11, 2026

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

2 IoCs
Read original article ↗

AI Summary

Researchers from the University of Birmingham and Fuzzware discovered that malicious SIM cards can exploit the RUN AT proactive command to execute attacker-controlled code on vulnerable cellular IoT devices. The attack affects devices using certain Quectel modules and select smartphones like the OPPO Reno 14 F 5G and ASUS Zenfone 9, all running Qualcomm communication processors. By issuing AT commands through a hostile SIM, attackers can achieve code execution, downgrade network connections to insecure 2G, or exfiltrate files via TFTP and SMTP. A specific vulnerability in the Quectel EC25AFXDGA module's atfwd_daemon enables remote code execution due to an unsafe format string and insufficient character filtering. The issue has been disclosed to vendors, but no public advisories or patches are widely available yet.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Filename atfwd_daemon Details →
GitHub Repo CATana Details →