[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$flEzRvOuizm4NXx7YWahDSSvEYW0OU8R4a2qEx3OHwaA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"e920d56f-bd6b-4805-9a96-4c1f582c2418","malicious-sim-cards-can-hijack-cellular-iot-modems-via-run-at-command","a3c85a26-baf2-4293-bc5d-b0748104f267","Malicious SIM Cards Can Hijack Cellular IoT Modems via 'RUN AT' Command","Researchers found that a standard SIM card feature — the 'RUN AT' command — can be weaponized to execute arbitrary attacker code directly inside cellular modems, affecting 9 of 26 tested devices including EV chargers and industrial routers. The root problem is that a trusted hardware component (the SIM) is granted unrestricted console access to the modem without sufficient validation or access controls. This matters because IoT devices are widely deployed in critical infrastructure and are rarely monitored or patched, making them high-value, low-visibility targets. A compromised SIM — whether inserted physically or obtained through a rogue mobile carrier — can silently take over a device at the firmware level, bypassing traditional software-layer defenses.","**Immediate actions:**\n- Disable the 'RUN AT' command interface on all affected modems where vendor documentation or firmware settings permit it.\n- Audit your IoT device inventory to identify which units use Qualcomm or Quectel chipsets and flag them as high-priority for patching.\n- Restrict physical access to SIM card slots on deployed IoT devices to prevent unauthorized SIM swaps.\n\n**Long-term improvements:**\n- Require vendors to provide firmware updates that disable or restrict the 'RUN AT' interface by default before deploying new IoT hardware.\n- Establish a supply chain vetting process that includes modem firmware security assessments prior to procurement.\n- Implement network segmentation to isolate cellular IoT devices from critical OT\u002FIT networks, limiting lateral movement if a device is compromised.\n\n**Detection measures:**\n- Deploy anomaly-based monitoring on IoT device traffic to detect unexpected command-and-control patterns or unusual data exfiltration.\n- Log all modem configuration changes and SIM authentication events, routing alerts to a centralized SIEM for review.\n- Conduct periodic penetration testing of cellular IoT assets, specifically targeting SIM-to-modem attack surfaces.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 12: Network Infrastructure Management","CIS Control 16: Application Software Security","NIST SP 800-53 CM-6: Configuration Settings","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-213: IoT Device Cybersecurity Guidance","ETSI EN 303 645: Cybersecurity for Consumer IoT","IEC 62443-3-3: Industrial Automation and Control System Security","NIST CSF PR.AC-3: Remote Access Management","NIST CSF DE.CM-7: Monitoring for Unauthorized Activity","published","2026-08-11T14:22:42.181345+00:00","2026-08-11T14:22:41.85+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fa-malicious-sim-card-can-run-attacker.html","a-malicious-sim-card-can-run-attacker-code-inside-the-modems-behind-cellular-iot-c2a228","A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]