[ RECORD YEAR ]2019

Simjacker: Global Surveillance via S@T Browser SIM Application Toolkit

AdaptiveMobile Security disclosed Simjacker, an exploit abusing legacy S@T Browser technology on SIM cards across 30+ countries to track subscriber location without user awareness.

THREAT SEVERITY
9.4 / 10
Target TechnologyS@T Browser (SIMalliance), Binary SMS (TP-PID 0x7F / Port 208), USIM
OSI Network LayerLayer 7 / SIM Application Toolkit (STK)
Threat Actor / AttributionCommercial Surveillance / Cyber Intelligence Firm
Protocol StandardSIMalliance S@T 01.00 / 3GPP TS 11.14 (SIM Toolkit)

01Video Presentation & Conference Keynote

02Deep-Dive Technical Analysis

Attackers sent specially crafted binary SMS messages containing SIM Toolkit (STK) bytecode commands (e.g., `PROVIDE LOCAL INFORMATION` and `SEND SHORT MESSAGE`) addressed to the S@T Browser application running on the subscriber's SIM card. The SIM executed the bytecode without displaying any alert, queried the modem for the serving Cell ID and IMEI, and transmitted the location data back to the attacker via an automated covert SMS.

03Vulnerability & Exploit Flow

Exploit Vector

Malicious binary SMS bytecode execution on legacy SIM browser applets.

04Recommended Defense & Mitigation Protocol

Operator Hardening Strategy

Deploy SMS-C binary filtering for S@T Browser ports and remove legacy STK applets from operator USIM profiles.

05Security Impact & Geopolitical Consequence

Compromised millions of devices across multiple continents without requiring malware on the operating system, forcing the GSMA to mandate strict binary SMS firewall filtering standards (GSMA FS.38).

06Authoritative Standards & External References

07Related Topic Cluster Records

TelcoSec Global Ecosystem · Academy & Enterprise Audits

Master 5G Core, SS7 Defense & Subsea Cable Auditing

Ready to turn your historical knowledge into certified hands-on expertise? Register free on TelcoSec Academy to access interactive lab challenges, or consult our enterprise team for carrier-grade signaling assessments and portable BTS hardware.

Hands-on SS7, Diameter & 5G SBA Firewall Defense
5G SA Zero Trust Security Architecture & ProLabs
Enterprise Carrier Auditing & Rogue Base Station Interception
Explore SaaS Academy Labs?Enterprise Consultancy (telco-sec.com)?
SaaS Academy free tier · Enterprise audits for operators