Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

thehackernews+1nytimes+1thehackernews+1Researchers at a small Palo Alto-based security firm used artificial intelligence to build a computer worm capable of hijacking WeChat Tencent Holdings Limited accounts across both iPhones and Android devices — without victims needing to answer a call, tap a link, or take any action at all. The tool, which the team assembled in roughly a week, underscores how AI is compressing the timeline for developing potent cyberattack capabilities.
The worm, dubbed WeWorm, exploits a memory corruption flaw in WeChat's VoIP stack, according to The Hacker News. An attacker calls a target through WeChat; if the recipient is a saved contact, merely letting the phone ring long enough triggers the compromise. Answering the call does not stop it. Declining the call within seconds does, but the attacker can simply try again later.thehackernews+1
Once a WeChat account is taken over, the attacker can read and send messages, make calls, and impersonate the victim — then use that person's contact list to spread the worm further. In a demonstration, one Android phone called an iPhone and seized its WeChat account while the phone was still ringing; the compromised iPhone then called a second Android device and did the same. Calif, the security company behind the research, said the worm could potentially reach hundreds of millions of devices within hours.ithinkdiff+3
Calif said it used AI to find the underlying bug and write the first working exploit in about two days; building the full worm took another week. The company used a combination of open-source and leading U.S.-based AI models but declined to specify which ones. Thai Duong, Calif's chief executive and a former Google security researcher, called the bug "exceptional" and said its simplicity and power would be "a dream come true" for hackers, according to The New York Times.nytimes+2
The disclosure follows a June paper from University of Toronto researchers who showed that publicly accessible AI models could power worms that adapt as they spread between devices, suggesting a broader trend in AI-enabled offensive security research.utoronto
Calif reported the vulnerability to Tencent in July and says no real-world attacks exploiting the flaw have been detected. Tencent released updated WeChat versions for Android and iOS in late August, and Calif confirmed on August 28 that the exploit was also blocked server-side, meaning users did not need to install an update to be protected. Tencent has not published a formal security advisory about the flaw. Calif also briefed White House officials before publicly disclosing the research.ithinkdiff+1