Malicious SIM Cards Can Hijack Cellular IoT Modems via 'RUN AT' Command
Researchers found that a standard SIM card feature — the 'RUN AT' command — can be weaponized to execute arbitrary attacker code directly inside cellular modems, affecting 9 of 26 tested devices including EV chargers and industrial routers. The root problem is that a trusted hardware component (the SIM) is granted unrestricted console access to the modem without sufficient validation or access controls. This matters because IoT devices are widely deployed in critical infrastructure and are rarely monitored or patched, making them high-value, low-visibility targets. A compromised SIM — whether inserted physically or obtained through a rogue mobile carrier — can silently take over a device at the firmware level, bypassing traditional software-layer defenses.
Tactical Insight
Immediate actions
- Disable the 'RUN AT' command interface on all affected modems where vendor documentation or firmware settings permit it.
- Audit your IoT device inventory to identify which units use Qualcomm or Quectel chipsets and flag them as high-priority for patching.
- Restrict physical access to SIM card slots on deployed IoT devices to prevent unauthorized SIM swaps.
Long-term improvements
- Require vendors to provide firmware updates that disable or restrict the 'RUN AT' interface by default before deploying new IoT hardware.
- Establish a supply chain vetting process that includes modem firmware security assessments prior to procurement.
- Implement network segmentation to isolate cellular IoT devices from critical OT/IT networks, limiting lateral movement if a device is compromised.
Detection measures
- Deploy anomaly-based monitoring on IoT device traffic to detect unexpected command-and-control patterns or unusual data exfiltration.
- Log all modem configuration changes and SIM authentication events, routing alerts to a centralized SIEM for review.
- Conduct periodic penetration testing of cellular IoT assets, specifically targeting SIM-to-modem attack surfaces.