logo

AdaptiveMobile Security Simjacker Technical Paper

ID: 8c125033-77c9-42ee-bfd4-00a500cd5bbc

STIX ID: report--8c125033-77c9-42ee-bfd4-00a500cd5bbc

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2019-10-03

Last Modified Date: 2019-10-03

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
AdaptiveMobile's Simjacker technical paper documents an actively exploited vulnerability in the S@T Browser SIM application that allows unauthenticated OTA (binary) SMS to execute SIM Toolkit commands, enabling silent retrieval and SMS exfiltration of handset location (Cell-ID) and IMEI. The authors attribute large-scale, sustained abuse by a sophisticated surveillance company (primarily targeting Mexican subscribers), describe attack structure, volumes (>25k messages to >1500 unique targets in a 31-day sample), multiple evasion and infrastructure techniques (including SS7 and A2P ingress, varied SMS encodings and exfiltration routes), enumerate affected countries/operators and potential additional misuse (fraud, DoS, malware facilitation), and provide mitigation recommendations for operators and subscribers.