AI-Built 'WeWorm' Threatens Billions of WeChat Users with Zero-Click Account Hijack

Context mode is active. Hover over any highlighted term to see its definition. Click a nested term to go deeper.
A US cybersecurity firm, Calif, leveraged artificial intelligence to create 'WeWorm', a dangerous zero-click worm that could have silently hijacked over a billion WeChat accounts on both Android and iOS devices. The groundbreaking AI-driven attack exploited a memory corruption flaw in WeChat voice-over-IP (VoIP) system, taking control of user accounts simply by making an incoming call, even if the victim never answered. Thankfully, Calif responsibly disclosed the vulnerability to Tencent, WeChat parent company, which has since rolled out crucial updates to mitigate the threat. This incident starkly highlights how AI is rapidly reshaping the cyber threat landscape, dramatically speeding up the development of sophisticated exploit that once took human teams months to build. Calif AI discovered the critical flaw and helped construct a fully functional Remote Code Execution (RCE) exploit within days, demonstrating how advanced capabilities are becoming more accessible even to less-skilled attackers. The potential for a self-spreading worm to compromise a user's entire contact list, leading to widespread data theft and impersonation, underscored the severity of this zero-click vulnerability. While Tencent reports no evidence of WeWorm being exploited in the wild, this episode serves as a critical warning. Cybersecurity experts are urging increased vigilance and collaboration between governments and tech firms to address the dual nature of AI in both offense and defense. Calif plans to reveal further technical details at an upcoming conference, but for now, the focus remains on patching similar vulnerabilities and understanding how AI-powered cyberattacks will evolve next.