Researchers proved that malicious SIM card attacks can execute attacker code inside the cellular modems running EV chargers, industrial routers, and telematics units. Six of eight tested industrial modules accepted the command. No mandatory patch exists yet, only a scattered, vendor-by-vendor response.
Malicious SIM card attacks just moved from theory to demonstrated fact for industrial hardware. Cellular IoT connections are on pace to reach 5.4 billion worldwide in 2026, according to IoT Analytics, and the module makers behind a large share of that growth just received a public lesson in a 40-year-old blind spot.
The vulnerability traces back to Proactive SIM, a legitimate cellular specification that lets a SIM card send commands directly to a device’s modem instead of only answering its requests. One of those commands, RUN AT, tells the modem to execute an AT command, the same control language used to operate modems since the 1980s, according to researchers from the University of Birmingham and security firm Fuzzware who presented the findings at the 2026 USENIX WOOT Conference in Baltimore. Using a custom toolkit called CATana, the team tested 26 devices: 18 smartphones and 8 cellular IoT modules used in EV chargers, industrial equipment, and connected cars.









