How a SIM can (and will) hack you: Security analysis of SIMs, attacks, and tools for research. π¨π»βπ»π«π±π©»πΎ
Security researchers Tomasz Lisowski and Marius Muench share the observation that has driven their research for several years: a SIM is an active computing platform capable of sending commands to phones, modems, and IoT devices.
To explore the SIM attack surface, the authors built custom SIM emulation and SIM-interface hardware and performed hostile-SIM testing, baseband fuzzing, lock-screen bypasses, and SIM-originated AT command testing. Iβve previously shared some of their results as well.
In this presentaion authors review the details of their setup and tests, some insights on new and very practical tools that will be useful for SIM research and give some tips to future researchers on where to look for some interesting bugs.
If youβre into mobile or telecom cybersecurity, this will be a must-read for you. However, the setups the authors share also have automotive and IoT/SCADA flavors, so it may be relevant to these fields too.
Enjoy the read!
More details:
A SIM Hacking Odyssey: Can a SIM hack YOU? [PDF]: https://troopers.de/downloads/troopers26/TR26_A_SIM_Hacking_Odyssey_QADSVY.pdf


