10% of SIM cards would be vulnerable to Simjacker

10% of SIM cards would be vulnerable to Simjacker

October 3, 2019 Off By admin

During the month of September, it was revealed that there is a security flaw in several SIM cards.

This security breach allowed some people via specific SMS to collect personal information about users of vulnerable SIM cards. This new form of hacking was called the "Simjacker."

This article will also interest you: Watch almost anyone via their SIM card, it's the Simjacker

The vulnerability was discovered by the company Adaptive Labs in early September. In its report published this month, the company explains that this security breach had been exploited since 2013 by other researchers, especially those from SR Labs.

As a reminder, let's explain how the SIMjacker works:

To exploit the flaw, hackers send a command SMS to the vulnerable SIM card, one text message. The SIM card in turn responds to hackers to provide them with the information they need to determine either geolocation, the type of device used, etc. All this happens without the SIM card user's knowledge. This is what drives cybersecurity researchers to be concerned about this security flaw that has been going on for five years. Especially since it can be easily used "for surveillance purposes."

So far we have no exact idea of the number of victims, or even exact figures for vulnerable SIM cards. Just an approximation of 10% of SIM cards in circulation.

According to SR Labs, the German company specializing in cybersecurity of mobile devices, this flaw is not to be overlooked as since 2013, it has been trying to report it and identify its consequences. and to do this, they had to test about 800 different SIM card models to justify the reality of SIMjacker attacks. In this regard they explain that the vulnerability allowing the Simjacker attack works thanks to a SMS as mentioned above.

It is a SMS that contains "Sim Toolkit" instructions that is directed to a single application called S@T, which is only installed on certain SIM card models in particular. Apparently this wouldn't be the only flaw that affects some categories of SIM cards. SR Labs talks about a second vulnerability that can be exploited on another Wireless Internet Browser application, a flaw discovered by the Ginno Security Lab, which published it on its website.

At this stage, we can conclude that there are now two possibilities for hackers to engage in Simjacker. SR Labs, in a survey, gives some figures:

– 9.4 percent of SIM cards that have been tested have an S@T app

– 10.7 percent of other SIM cards tested have Wireless Internet software Browser.

It is true that this panel is not representative, and what is certain is that not all SIM cards are necessarily involved in this security breach. This can be explained by the fact that SIM card and application configurations will vary according to telephone operators. For each mobile phone, there will be a particularity brought to the SIM card that it will use.

In the end, the Simjacker is indeed a reality. Maybe everyone is exposed in some way. The major problem with this vulnerability is that the user cannot protect themselves. They are obliged to rely on mobile operators who must provide an adequate solution to put an end to this security breach.

Now access an unlimited number of passwords!