/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers: “SimJacker”, a widespread SIM card-based vulnerability, is being exploited by a private actor “that works with governments to monitor individuals”

https://thehackernews.com/... #infosec #technews https://twitter.com/... @thehackersnews : What's more worrisome? According to researchers, a specific private company that works with Governments is actively exploiting #SimJacker vulnerability for at least 2 years to conduct targeted surveillance on mobile phone users across several countries. https://thehackernews.com/... https://twitter.com/... Doifeellucky / @do_i_feellucky : Ooof... it's all about scale huh? Does somebody still have illusions about mobile security? https://threatpost.com/... Dino A. Dai Zovi / @dinodaizovi : This blog post blew my mind. You can send an SMS to many SIMs that will cause the smartphone to open up a web browser to the specified URL?!? https://twitter.com/... Daniel Cuthbert / @dcuthbert : When an attack by Karsten Nohl from 6 years ago, is turned into a tool and people go wild. https://www.adaptivemobile.com/ ... Karsten has done amazing research into SS7 security and seemingly not listened to as he should have been https://www.theregister.co.uk/ ... Profdeibert / @rondeibert : “The main Simjacker attack involves a SMS containing a specific type of spyware-like code being sent to a mobile phone, which then instructs the UICC (SIM Card) within the phone to ‘take over’ the mobile phone” https://www.adaptivemobile.com/ ... Joseph Cox / @josephfcox : Statement from T-Mobile. So none of the major US telecos are impacted by this SIM vulnerability. Still around a billion devices elsewhere that are, according to AdaptiveMobile pic.twitter.com/7u45PUIUgU Joseph Cox / @josephfcox : Sprint says it is not impacted by this attack because it “does not use the vulnerable S@T browser on Sprint SIM cards.” It did talk to AdaptiveMobile through the responsible disclosure process though. Joseph Cox / @josephfcox : AT&T says “This is not something we use in the U.S., so we are not affected here.” @privacydigest : Simjacker attack exploited in the wild to track users for at least two years | ZDNet https://www.zdnet.com/... > #Simjacker attack abuses STK and S@T Browser technologies installed on some SIM cards. @teriradichel : I remember when the CTO of a security company scoffed when I predicted attacks like this on mobile networks. It was only a matter of time. https://twitter.com/...

Threatpost Lindsey O'Donnell

Discussion

  • @josephfcox Joseph Cox on x
    This is a pretty wild attack. Leveraging vectors in the SIM card to get location data, other information on targets. Because it's SIM card, its platform agnostic. Being used by a company that sells surveillance capabilities to governments https://www.adaptivemobile.com/ ... pic.…
  • @josephfcox Joseph Cox on x
    After originally declining to comment and only giving an answer after being pushed, Verizon says “We have no indication to believe this impacts Verizon.”
  • @josephfcox Joseph Cox on x
    Here is some comment from the GSMA. It doesn't have data on which countries were impacted (although others likely will) pic.twitter.com/itTNAXjGAH
  • @thehackersnews @thehackersnews on x
    💥 SimJacker #Vulnerability (0-day under active attack) A new SIM card-based flaw could allow remote attackers to hijack and spy on any phone just by sending an SMS - regardless of which handset the victim is using. Read details — https://thehackernews.com/... #infosec #technews h…
  • @thehackersnews @thehackersnews on x
    What's more worrisome? According to researchers, a specific private company that works with Governments is actively exploiting #SimJacker vulnerability for at least 2 years to conduct targeted surveillance on mobile phone users across several countries. https://thehackernews.com/…
  • @do_i_feellucky Doifeellucky on x
    Ooof... it's all about scale huh? Does somebody still have illusions about mobile security? https://threatpost.com/...
  • @dinodaizovi Dino A. Dai Zovi on x
    This blog post blew my mind. You can send an SMS to many SIMs that will cause the smartphone to open up a web browser to the specified URL?!? https://twitter.com/...
  • @dcuthbert Daniel Cuthbert on x
    When an attack by Karsten Nohl from 6 years ago, is turned into a tool and people go wild. https://www.adaptivemobile.com/ ... Karsten has done amazing research into SS7 security and seemingly not listened to as he should have been https://www.theregister.co.uk/ ...
  • @rondeibert Profdeibert on x
    “The main Simjacker attack involves a SMS containing a specific type of spyware-like code being sent to a mobile phone, which then instructs the UICC (SIM Card) within the phone to ‘take over’ the mobile phone” https://www.adaptivemobile.com/ ...
  • @josephfcox Joseph Cox on x
    Statement from T-Mobile. So none of the major US telecos are impacted by this SIM vulnerability. Still around a billion devices elsewhere that are, according to AdaptiveMobile pic.twitter.com/7u45PUIUgU
  • @josephfcox Joseph Cox on x
    Sprint says it is not impacted by this attack because it “does not use the vulnerable S@T browser on Sprint SIM cards.” It did talk to AdaptiveMobile through the responsible disclosure process though.
  • @josephfcox Joseph Cox on x
    AT&T says “This is not something we use in the U.S., so we are not affected here.”
  • @privacydigest @privacydigest on x
    Simjacker attack exploited in the wild to track users for at least two years | ZDNet https://www.zdnet.com/... > #Simjacker attack abuses STK and S@T Browser technologies installed on some SIM cards.
  • @teriradichel @teriradichel on x
    I remember when the CTO of a security company scoffed when I predicted attacks like this on mobile networks. It was only a matter of time. https://twitter.com/...