Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

New eSIM Hack Let Attackers Clone Profiles and Hijack Phone Identities

Posted on July 11, 2025July 11, 2025 By CWS

A important vulnerability in eSIM know-how permits attackers to clone cellular subscriber profiles and hijack cellphone identities. 

AG Safety Analysis revealed they broke the safety of Kigen eUICC playing cards with GSMA client certificates, marking what they declare is the primary profitable public hack in opposition to client GSMA eUICC and EAL-certified GSMA safety chips.

The analysis staff extracted personal ECC keys from compromised eUICC playing cards and demonstrated the flexibility to obtain eSIM profiles from main cellular community operators, together with AT&T, Vodafone, O2, Orange, and T-Cell, in cleartext format. 

Key Takeaways1. Researchers efficiently hacked Kigen eUICC playing cards, extracting personal keys and downloading eSIM profiles from main carriers in unencrypted format.2. Reside checks demonstrated full cellphone identification hijacking, with attackers intercepting all calls, SMS, and two-factor authentication codes undetected.3. The vulnerability impacts over 2 billion SIMs, permitting one compromised certificates to entry any cellular operator’s eSIM profiles globally.4. Kigen deployed safety patches to tens of millions of eSIMs whereas GSMA shut down check profiles and up to date business safety specs.

This breakthrough represents a major safety breach within the eSIM ecosystem, which processes over 2 billion SIMs enabled by Kigen’s safe SIM OS, in line with firm press releases.

Java Card Flaw Permits Distant Cloning

The assault exploits elementary flaws in Java Card Digital Machine implementation, particularly concentrating on kind confusion vulnerabilities much like points reported in 2019. 

The researchers developed a Proof of Idea that mimics malicious applet set up over the OTA SMS-PP protocol (Brief Message Service Level to Level).

The vulnerability permits attackers to bypass a number of safety mechanisms, together with EAL4/5 certification, side-channel assault countermeasures, and Java Card Runtime security measures. 

The assault vector requires both bodily entry to the goal card together with information of set up keys or distant exploitation via OTA channels.

Important technical components compromised embrace community operators’ OPc keys and Authentication Administration Subject (AMF) – two important secret keys embedded in eSIM profiles that needs to be “safeguarded by community operators at any value”. 

The researchers’ toolkit implements a Primary Safety Test (BSC) command that evaluates Java Card-capable eUICC safety via varied bytecode vulnerability assessments.

Probably the most alarming demonstration concerned profitable eSIM cloning checks carried out on Orange Poland’s community in July 2025. 

Researchers put in equivalent Orange eSIM profiles on two completely different bodily eUICC playing cards and demonstrated full subscriber identification hijacking.

When the malicious system was activated, it instantly started receiving all calls and SMS messages meant for the reputable subscriber.

This cloning functionality poses extreme dangers for two-factor authentication techniques, as attackers can intercept SMS-based verification codes for providers like Gmail and e-banking platforms. 

The researchers confirmed that reputable customers stay unaware of the hijacking, as no seen hint seems on the consumer finish.

Kigen has responded by implementing kind security checks throughout roughly 180 JavaCard bytecode directions and coordinating with GSMA to replace the TS.48 Generic Check Profile specification. 

The corporate distributed patches to tens of millions of eSIMs and issued a safety bulletin detailing mitigation methods. 

GSMA has additionally revealed new software notes and shut down all check profiles to forestall unauthorized Java Card software installations.

Examine reside malware habits, hint each step of an assault, and make sooner, smarter safety selections -> Attempt ANY.RUN now 

Cyber Security News Tags:Attackers, Clone, eSIM, Hack, Hijack, Identities, Phone, Profiles

Post navigation

Previous Post: Iranian-Backed Pay2Key Ransomware Resurfaces with 80% Profit Share for Cybercriminals
Next Post: Securing Data in the AI Era

Related Posts

Malicious Go Module Package as Fast SSH Brute Forcer Exfiltrates Passwords via Telegram Cyber Security News
The Most Active RAT Uses New Stagers and Loaders to Bypass Defenses Cyber Security News
Reddit to Block Internet Archive as AI Companies Have Scraped Data From Wayback Machine Cyber Security News
Advanced Endpoint Threat Detection in 2025 Network Environments Cyber Security News
Rise in Phishing Activity Using Spoofed SharePoint Domains With Sneaky2FA Techniques Cyber Security News
Hackers Weaponize Compiled HTML Help to Deliver Malicious Payload Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • 28,000+ Citrix Servers Exposed to Active 0-Day RCE Vulnerability Exploited in the Wild
  • Someone Created First AI-Powered Ransomware Using OpenAI’s gpt-oss:20b Model
  • Hackers Weaponize Trust with AI-Crafted Emails to Deploy ScreenConnect
  • CISA releases New ICS Advisories Surrounding Vulnerabilities and Exploits
  • Attacker Context and Historical iOS Zero-Click Similarities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • 28,000+ Citrix Servers Exposed to Active 0-Day RCE Vulnerability Exploited in the Wild
  • Someone Created First AI-Powered Ransomware Using OpenAI’s gpt-oss:20b Model
  • Hackers Weaponize Trust with AI-Crafted Emails to Deploy ScreenConnect
  • CISA releases New ICS Advisories Surrounding Vulnerabilities and Exploits
  • Attacker Context and Historical iOS Zero-Click Similarities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News