Researchers used AI to build WeChat worm that spreads via calls

Posted under: AI technologies
Date: 2026-09-10
Researchers used AI to build WeChat worm that spreads via calls | Justo Global

Security researchers at Palo Alto firm Calif say they used AI to find a flaw in WeChat and build a worm called WeWorm. The worm spreads through WeChat calls. An attacker who is already on the victim’s friend list places a call. The account can be taken over while the phone is still ringing. The victim does not need to answer. The compromised account can then call the owner’s contacts and repeat the process. Calif calls it the first zero-click worm to spread through WeChat calls on both iOS and Android. A successful attack gives full control of the WeChat account, including messages and calls. The firm says the bug is a memory corruption issue in the calling stack. Working with AI, the team found the bug and wrote an initial exploit in about two days, then built the worm in another week. Tencent confirmed the vulnerability, said it fixed it, and stated it has no reason to believe users were affected. No public advisory or CVE has appeared.

Read more at: thenextweb.com

Related videos

Researchers used AI to build WeChat worm that spreads via calls

Posted under: AI technologies
Date: 2026-09-10
Researchers used AI to build WeChat worm that spreads via calls | Justo Global

Security researchers at Palo Alto firm Calif say they used AI to find a flaw in WeChat and build a worm called WeWorm. The worm spreads through WeChat calls. An attacker who is already on the victim’s friend list places a call. The account can be taken over while the phone is still ringing. The victim does not need to answer. The compromised account can then call the owner’s contacts and repeat the process. Calif calls it the first zero-click worm to spread through WeChat calls on both iOS and Android. A successful attack gives full control of the WeChat account, including messages and calls. The firm says the bug is a memory corruption issue in the calling stack. Working with AI, the team found the bug and wrote an initial exploit in about two days, then built the worm in another week. Tencent confirmed the vulnerability, said it fixed it, and stated it has no reason to believe users were affected. No public advisory or CVE has appeared.

Read more at: thenextweb.com
Open-source: The power of collective information

Open-source: The power of collective information

Open-source: The power of collective infor...

Elevate Your Sales Using Managed Services - Don't Miss Out!

Elevate Your Sales Using Managed Services - Don't Miss Out!

Elevate Your Sales Using Managed Services ...

How CRM Transforms Customer Relationships? #crm #technology #technews #business #businessautomation

How CRM Transforms Customer Relationships? #crm #technology ...

How CRM Transforms Customer Relationships?...