Jump to content

That's Jack Yo - Simjacker attack exploits 1 billion+ SIM cards via hidden SMS messages, active campaigns in progress

rcmaehl

Sources:

ArsTechnica (quote source)
AdaptiveMobile (Image source)
Statements from US Carriers

 

Summary:
A flaw in an applet embedded in SIM cards has been actively used in the last 2 years to track users and perform other activities.

 

Media:
S_attackflow.jpg
 

Quotes/Excerpts:

Quote

Hackers are actively exploiting a critical weakness found in most mobile phones to...track the location of users and...carry out other nefarious actions, researchers warned on Thursday. The...Simjacker exploits work across a wide range of mobile devices, regardless of the hardware or software they rely on, researchers with telecom security firm AdaptiveMobile Security said. The attacks work by exploiting an interface intended to be used solely by cell carriers so they can communicate directly with the SIM cards. Simjacker abuses the interface by sending commands that track the location and obtain the IMEI identification code of phones. They might also cause phones to make calls, send text messages, or perform a range of other commands. Over the past two years, AdaptiveMobile Security researchers said, they have observed devices from “nearly every manufacturer being successfully targeted to retrieve location.” Device makers include Apple, ZTE, Motorola, Samsung, Google, Huawei, and even those who produce Internet-of-things products that contain SIM cards. While basic attacks work on virtually all devices, more advanced variations—such as making a call—would work only on specific phones that don’t require users to confirm they want the call to go through. The attacks were “developed by a specific private company that works with governments to monitor individuals,”  "In one country we are seeing roughly 100-150 specific individual phone numbers being targeted per day via Simjacker attacks, although we have witnessed bursts of up to 300 phone numbers attempting to be tracked in a day, the distribution of tracking attempts varies." The attacks work by sending targeted phones an SMS message that contains special formatting and commands that get passed directly to the universal integrated circuit card, which is the computerized smart card that makes modern SIMs work. The message contains commands for software—called the S@T browser—that runs on the SIM card.  The researchers said other commands UICCs are capable of executing include: 

  • PLAY TONE
  • SEND SHORT MESSAGE
  • SET UP CALL
  • SEND USSD
  • SEND SS
  • PROVIDE LOCAL INFORMATION (including location, battery, network, and language)
  • POWER OFF CARD
  • RUN AT COMMAND
  • SEND DTMF COMMAND
  • LAUNCH BROWSER
  • OPEN CHANNEL (CS BEARER, DATA SERVICE BEARER, LOCAL BEARER, UICC SERVER MODE, etc.)
  • SEND DATA
  • GET SERVICE INFORMATION
  • SUBMIT MULTIMEDIA MESSAGE
  • GEOGRAPHICAL LOCATION REQUEST

In response to the attacks, the SIMalliance—an industry group representing major UUIC makers—issued a new set of security guidelines for cellular carriers. The recommendations include:

  • Implementing filtering at the network level to intercept and block “illegitimate binary SMS messages” and
  • Making changes to the security settings of SIM cards issued to subscribers.

 

My Thoughts:

Anyone that understands the basics of how SIM cards work honestly shouldn't be surprised at this revelation. SIM cards are IN FACT a computer. They have their own processor, storage, and RAM as well as a variety of applications installed, some accessible via the phone and some not. SIM cards are extremely capable of a variety of tasks and should definitely be considered one of the weakest links in a mobile device. Regardless, it does look like some government contractors and other government entities are actively using this exploit. Thankfully, it looks like most US carriers should not be affected... How non-US carriers are affected are yet to be seen.

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

30 minutes ago, VegetableStu said:

inb4 someone gets one to run minecraft

Minecraft, no.


Atari Basic. Maybe?

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

39 minutes ago, huilun02 said:

How bout make a phone with a GPS and cellular radio killswitch?

Haven't looked into the details in a while but isn't that what the Librem 5 intends to do?

 

Among other things also ship with a linux distro because android is becoming more and more of an over bloated cluster fuck for google to spy on you.

Link to comment
Share on other sites

Link to post
Share on other sites

Can't wait for Apple to release a blog post telling their customers that this "only affected a small ethnic group and not 1 billion people," that they "take security very seriously," and that you should continue buying iPhones.

 

I'm curious if anything is going to be done over this, especially in certain countries.

if you have to insist you think for yourself, i'm not going to believe you.

Link to comment
Share on other sites

Link to post
Share on other sites

Is this related to the SIM swapping attacks on twitter recently?

Specs: Motherboard: Asus X470-PLUS TUF gaming (Yes I know it's poor but I wasn't informed) RAM: Corsair VENGEANCE® LPX DDR4 3200Mhz CL16-18-18-36 2x8GB

            CPU: Ryzen 9 5900X          Case: Antec P8     PSU: Corsair RM850x                        Cooler: Antec K240 with two Noctura Industrial PPC 3000 PWM

            Drives: Samsung 970 EVO plus 250GB, Micron 1100 2TB, Seagate ST4000DM000/1F2168 GPU: EVGA RTX 2080 ti Black edition

Link to comment
Share on other sites

Link to post
Share on other sites

33 minutes ago, williamcll said:

Is this related to the SIM swapping attacks on twitter recently?

No, that's irrelevant, SIM swapping involves social engineering, not a software/hardware exploit.

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, Crowbar said:

Haven't looked into the details in a while but isn't that what the Librem 5 intends to do?

 

Among other things also ship with a linux distro because android is becoming more and more of an over bloated cluster fuck for google to spy on you.

Huh, that might end up being my next phone. Seems really nice tbh

I spent $2500 on building my PC and all i do with it is play no games atm & watch anime at 1080p(finally) watch YT and write essays...  nothing, it just sits there collecting dust...

Builds:

The Toaster Project! Northern Bee!

 

The original LAN PC build log! (Old, dead and replaced by The Toaster Project & 5.0)

Spoiler

"Here is some advice that might have gotten lost somewhere along the way in your life. 

 

#1. Treat others as you would like to be treated.

#2. It's best to keep your mouth shut; and appear to be stupid, rather than open it and remove all doubt.

#3. There is nothing "wrong" with being wrong. Learning from a mistake can be more valuable than not making one in the first place.

 

Follow these simple rules in life, and I promise you, things magically get easier. " - MageTank 31-10-2016

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

On 9/12/2019 at 8:47 PM, VegetableStu said:

inb4 someone gets one to run minecraft

Or doom and skyrim, everything must run doom and skyrim.

Link to comment
Share on other sites

Link to post
Share on other sites

can't get simjacked without a sim card. ?

I live in misery USA. my timezone is central daylight time which is either UTC -5 or -4 because the government hates everyone.

into trains? here's the model railroad thread!

Link to comment
Share on other sites

Link to post
Share on other sites

On 9/12/2019 at 10:06 PM, huilun02 said:

How bout make a phone with a GPS and cellular radio killswitch?

You mean Airplane mode? 

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×