Hackers could use malicious SIM cards to carry out cyber-attacks on mobile devices like smartphones, researchers have said.

Subscriber Identity Modules, or SIM cards, are the secure element used to connect devices to a mobile network, but they can pose severe security risks when compromised and allow bad actors to gather information about a device, interfere with its connectivity, and serve as entry point for further cyberattacks.

University of Birmingham researchers exploited a feature known as Proactive SIM to allow them to send a limited number of special commands directly to a device’s modem. One of them allows the SIM to request the execution of so-called AT commands – the same type of commands used to control and configure modems since the 1980’s.

The researchers investigated 26 representative devices: 18 smartphones and eight cellular-connected IoT modules, including modules commonly embedded in electric vehicle chargers, industrial equipment, and connected cars.

After identifying...