AI-built worm hijacks WeChat accounts with a single unanswered call
Researchers at US security firm Calif used AI to build a zero-click worm (WeWorm) that hijacks WeChat accounts via a missed call, spreading automatically through contacts. Tencent patched the vulnerability after being notified, but the incident highlights how AI accelerates cyber threats and underscores the need for global cooperation, per the researchers.
Bottom line — Calif warned that AI could let attackers compromise over a billion WeChat accounts within hours, per The New York Times.
Go deeper (6)
- The worm exploits a memory corruption bug in WeChat's VoIP system, requiring no user interaction beyond a call, according to Calif's research.
- Calif said it identified the vulnerability and built the first remote code execution exploit in two days, then spent a week building the worm, per PC Magazine.
- Tencent confirmed the flaw and deployed a server-side fix in late August, with no evidence of real-world exploitation, per the South China Morning Post.
- Vinh Nguyen, a former NSA chief data scientist, told The New York Times the worm could 'propagate exponentially' and reach hundreds of millions of devices within hours.
- Calif urged US-China collaboration on AI security, saying 'keeping billions of people safe online shouldn't be one of them,' per the South China Morning Post.
- The disclosure follows an open letter from OpenAI and over 100 tech companies warning of a wave of AI-enabled cyberattacks, per The New York Times.