Using a custom tool named CATana, the researchers tested 26 representative devices including smartphones and IoT modules used in electric vehicle chargers, connected cars, and industrial equipment. A built-in feature known as “Proactive SIM” allows a SIM card to issue commands directly to a device’s modem. Created in the 1980s to control dial-up modems, AT commands act as a skeleton key to a device’s cellular hardware. After confirming that several test devices processed SIM-originated AT commands, the CATana toolkit exposed severe security flaws in the resulting interface. Hostile SIMs can enter the wild through infected SIM software updates, rogue cellular operators abusing remote management platforms, or supply-chain tampering during manufacturing.