SIM Card Attack May Affect Over 1 Billion Mobile Phones Worldwide

Stu Sjouwerman | Nov 15, 2019

Using SMS messaging, attackers can use phishing tactics to hijack mobile devices using a legacy piece of SIM code, called the S@T Browser, to execute commands as part of a more sophisticated attack.Businesswoman holding tablet pc entering password. Security concept

Researchers at Adaptive Mobile Security have announced the discovery of a new mobile phone SIM vulnerability dubbed Simjacker. Believing this vulnerability to be over 2 years old and present on SIM cards in mobile devices in over 30 countries, the potential threat for this new vulnerability is significant.

According to Adaptive, an SMS message is sent to the phone with specific encoding that causes the SIM Card to call on an embedded library called the S@T Browser to process the commands. Location and device information can be exfiltrated, along with remote execution of commands on the mobile device, including:

  • Sending outbound SMS messages
  • Placing phone calls
  • Opening a web page

These kinds of actions could play a role in larger attacks. For example:

  • CEO gift card and fraud scams could be initiated via text message
  • Outbound calls could be used to listen in on conversations
  • Malware could be installed by directing the phone’s browser to a malicious website

This is a very powerful and nasty vulnerability. According to Adaptive, the carriers are working to block such messages, as the text messages don’t require user interaction. But because the attack following the compromise of a mobile device will need to leverage traditional methods of attack (usually involving some form of social engineering), users should be vigilant against attacks coming from mobile text messaging, mobile email, etc.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.