
The GoSIM attack is a novel mobile network fraud technique that extracts SIM card information without the secret key and exploits weak authentication policies in 2G, 3G, 4G, and 5G networks. By cloning SIM data onto programmable SIM cards, attackers can impersonate victims, bypassing authentication in networks with lax policies, enabling fraud such as unauthorized calls and access to services like WhatsApp.
SIM card swapping attacks have become a prevalent threat, where attackers use social engineering to transfer a victim's phone number to a new SIM card, enabling fraud. Building on this, the GoSIM attack introduces a new technique that exploits weak authentication policies in mobile networks from 2G through 5G to commit fraud.
The GoSIM attack extracts essential SIM card information—excluding the secret key (KI)—and leverages weak authentication policies in mobile networks to impersonate a subscriber. This allows attackers to connect to the network and perform fraudulent activities without needing the secret key.
A SIM card stores subscriber identity information such as the International Mobile Subscriber Identity (IMSI), temporary identities, and other operator-specific data. It also contains a secret key (KI) used for authentication, which is securely stored and not directly accessible.
Physical access to the victim's SIM card is required. Using SIM card readers and interfaces like pySIM shell, attackers can read elementary files such as the IMSI and Integrated Circuit Card Identifier (ICCID). Some SIM cards lack PIN protection, making it easier to read these files.
Mobile networks consist of two main components:
Authentication ensures both the client and network verify each other's identity. In 2G, only the network authenticated the client, making it vulnerable to fake base stations. From 3G onwards, mutual authentication was introduced.
Authentication policies define how often and under what conditions authentication procedures are triggered. These can be:
Weak authentication policies have longer intervals or higher event thresholds, increasing the window for exploitation.
If the network has a weak authentication policy and does not trigger authentication frequently, the attacker can connect successfully without the KI, impersonating the victim.
The researchers demonstrated the attack using a Raspberry Pi connected to a SIM card reader and a programmable SIM card. They tested various operators across countries including Spain, Netherlands, Germany, Singapore, and Canada.
They also showed the ability to use the cloned SIM to access services like WhatsApp, bypassing two-factor authentication by receiving verification codes via calls or SMS.
Usually, only one SIM card can handle services at a time due to race conditions. If the victim's phone is off or in airplane mode, the cloned SIM will receive calls and SMS.
Generally, no. The baseband uses volatile memory, so once the device is off, traces are lost. Network operators cannot distinguish between the legitimate and cloned SIM during the attack.
The researchers have not tested eSIMs yet; this remains an area for future work.
The GoSIM attack reveals significant vulnerabilities in mobile network authentication policies worldwide. While requiring physical access to the victim's SIM card, the attack can bypass authentication in networks with weak policies, enabling fraud across all mobile generations. Strengthening authentication policies and user security practices are essential to mitigate this threat.
For detailed technical information, the researchers have published a comprehensive paper available on ResearchGate.
This research highlights the importance of robust authentication in mobile networks and the evolving landscape of SIM card security threats.
Paste a YouTube link and let Magica create the key takeaways.
Summarize another video