Sunday, June 1, 2025
HomeCyber Security News861 Million SIM cards in 29 Countries are Vulnerable to Simjacker Attacks

861 Million SIM cards in 29 Countries are Vulnerable to Simjacker Attacks

Published on

SIEM as a Service

Follow Us on Google News

Simjacker vulnerability disclosed last month, being exploited by attackers for more than two years. The vulnerability is based on SIM card technology.

The vulnerability relies on the S@T Browser technology, which has no authentication enabled by default, it let attackers execute any command on SIM card without user consent.

Simjacker Attack

All the attacker require is to send a message which includes spyware-like code to the targeted mobile phone, the message instructs the SIM cards to send to another message with details such as location/terminal information, without any user interaction.

- Advertisement - Google News

For a successful attack, the following conditions to be satisfied

  • Successful SMS Delivery
  • SIM should use S@T Browser technology

The vulnerability was disclosed by Adaptive Mobile Security, according to the new report published by the company, 61 Mobile Operators in the 29 countries use S@T Browser technology. 861 Million active SIM cards use this technology.

Attack Volume

Researchers observed over 25k Simjacker messages are attempted to send for more than 1500 Unique Identifiers. Most of the targeted users are from Mexico and few users from Colombia and Peru.

In a given single day 69% of users are targeted and few users are targeted every single day. The primary objective of the attack is to get the geo-location and IMEI of the device.

Following are the additional commands executed

  • Display Text (Test Messages),
  • Launch Browser (Test websites),
  • Set Up Call (test recipient number) and
  • Send USSD (test PIN change)

“Researchers observed that over 860 Simjacker Attack sub-variants in the actual SMS Packet and they are sent in 1000 different types of encoding combinations, the actual Simjacker Attack packet itself was done to also potentially avoid defenses, or potentially to tailor the attack per specific Sim card type.”

Countries Affected

At least 29 countries still S@T Browser with the no-security level set. According to an analysis report, 61 Mobile Operators using this technology, around 90% of the SIM card issued by the operators use this technology.

Countries Affected
  • Asia: Saudi Arabia, Iraq, Palestine and Lebanon.
  • Africa: Nigeria, Ghana, Benin, Ivory Coast, and Cameroon.
  • North America: Mexico, Guatemala, Honduras, Costa Rica, Nicaragua, Belize, El Salvador, Dominican Republic, and Panama.
  • Europe: Italy, Bulgaria, and Cyprus.
  • South America: Peru, Colombia, Brazil, Ecuador, Chile, Argentina, Uruguay, and Paraguay.

Countries /operators are using the technology which we did not observe directly. This is because our search was based on a side effect of looking for attacks on users, not looking for ordinary activity, researchers said.

Researchers believe operators in other countries may also use this technology, but as we did not directly observe S@T Browser messaging at a no security Level.

The attack can be used in any of the following scenarios

  • Fraud Applications
  • Advanced Location Tracking
  • Assistance in Malware Deployment
  • Denial of Service
  • Information Retrieval
  • Misinformation

Similar to the Simjacker attack, another vulnerability was observed at the end of September dubbed WIBattack which impacts millions of od subscribers around the globe.

S@T browser and WIB

Adaptive security researchers also looked at WIB application, when used with no security level is used in far fewer countries: 7 and operators:8. These countries are spread over Eastern Europe, Central America, Asia, and West Africa.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Attackers Exploit Microsoft Entra Billing Roles to Escalate Privileges in Organizational Environments

A startling discovery by BeyondTrust researchers has unveiled a critical vulnerability in Microsoft Entra...

Threat Actors Exploit Google Apps Script to Host Phishing Sites

The Cofense Phishing Defense Center has uncovered a highly strategic phishing campaign that leverages...

Dadsec Hacker Group Uses Tycoon2FA Infrastructure to Steal Office365 Credentials

Cybersecurity researchers from Trustwave’s Threat Intelligence Team have uncovered a large-scale phishing campaign orchestrated...

Beware: Weaponized AI Tool Installers Infect Devices with Ransomware

Cisco Talos has uncovered a series of malicious threats masquerading as legitimate AI tool...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Attackers Exploit Microsoft Entra Billing Roles to Escalate Privileges in Organizational Environments

A startling discovery by BeyondTrust researchers has unveiled a critical vulnerability in Microsoft Entra...

Threat Actors Exploit Google Apps Script to Host Phishing Sites

The Cofense Phishing Defense Center has uncovered a highly strategic phishing campaign that leverages...

Dadsec Hacker Group Uses Tycoon2FA Infrastructure to Steal Office365 Credentials

Cybersecurity researchers from Trustwave’s Threat Intelligence Team have uncovered a large-scale phishing campaign orchestrated...