35
Simjacker
Technical Report ©2019
AdaptiveMobile Security Figure 14: Count of Vulnerable Countries & Operators for ST and WIB In general, we
found that the WIB application, when used with no security level is used in far less countries 7 and operators, as per Figure 14, albeit the operators that it is currently used in are quite large relatively (based on subscriber numbers. These countries are spread over Eastern Europe,
Central America, Asia and West Africa, there are no single regions of heavy use as is evident for usage of the ST Browser technology. The same issues arise in trying to guess the number of affected SIM cards, a range of reference points is in the diagram below.
The most probable, conservative estimate would be that it would be a range in the low hundreds of millions of SIM cards. The potential mitigations are roughly similar to the ST Browser. On the network side SMS filtering would be required to block these messages. However, on the SIM side, upgrading the security of the SIM implementation needs to focus on WIB-specific security configuration files. This is because the security for incoming and outgoing message does not depend on the Minimum Security Level (MSL) associated with the application, rather it is determined by specific WIB security configuration files.
36
Simjacker Technical Report
©2019 AdaptiveMobile Security
8 Recommendations
8.1
Share with your friends: