2 Sources
[1]
A.I. Models Built a Computer Worm That Could Rapidly Hack WeChat Accounts
Dustin Volz covers cybersecurity and intelligence, and reported from Washington. A friend you haven't heard from in a while suddenly calls. You don't pick up, but in a matter of seconds, the damage is already done. The call wasn't actually from an old companion looking to reconnect, but from a
[2]
Calif security firm built AI-powered WeChat worm WeWorm
Calif, a security company based in Palo Alto, California, disclosed today that it built a self-spreading worm capable of hijacking WeChat accounts by exploiting a memory corruption flaw in the app's voice-over-IP stack -- and did so with significant assistance from AI. The worm, named WeWorm,
Share
Copy Link
Security firm Calif developed WeWorm, the first AI-powered computer worm capable of hijacking WeChat accounts through a zero-click attack. The autonomous worm exploits a memory corruption flaw in WeChat's VoIP stack, spreading across iOS and Android without requiring user interaction. Tencent confirmed and patched the vulnerability affecting its 1.4 billion monthly active users.
Security firm Calif, based in Palo Alto, California, recently built an AI-powered worm that exposed critical vulnerabilities in WeChat, the messaging platform with over 1.4 billion active users each month
1
. The company developed the hacking tool in just over a week using advanced artificial intelligence models, demonstrating how AI-enabled cyberattacks are evolving at unprecedented speed. Thai Duong, chief executive of Calif, described the bug as "exceptional" and noted its simplicity and powerful abilities would be "a dream come true" for malicious hackers1
. The security firm builds these tools not to sell them but to strengthen defensive measures and expose weaknesses before threat actors can exploit them.
Source: NYT
The AI-powered computer worm, named WeWorm, represents the first known computer worm capable of spreading across both iOS and Android operating systems without requiring victims to click or tap anything
1
. The zero-click attack works by exploiting a memory corruption flaw in WeChat's voice-over-IP stack2
. Simply placing a call to a WeChat user is enough to hijack WeChat accounts, whether or not the target answers2
. Only declining the call within seconds of it ringing would prevent the exploit from succeeding. Once a WeChat account was compromised, the attacker could read and send private messages, make calls, and control the victim's account entirely1
. The worm then automatically dials numbers from the victim's contact list to extend the attack outward, enabling autonomous spread across networks like a highly contagious virus2
.A spokeswoman for Tencent, the Chinese technology company that owns WeChat, confirmed the vulnerability after being contacted by Calif
1
. The company stated it had fixed the issue and had no reason to believe it compromised security or affected any users, adding that no app updates were required by customers1
. The VoIP stack vulnerability allowed the worm to leverage software vulnerabilities that do not require clicking on a link or file to automatically deploy malicious code. Combined with other security bugs, an attacker could have used access to a WeChat account to fully compromise a victim's phone1
. Nearly all of WeChat's users are based in China, making the platform a significant target for cybersecurity threats.Related Stories
The discovery highlights growing concerns about the dual-use nature of AI and how advanced models could deliver a major advantage to malicious hackers in the short term. Calif relied on a combination of open-source AI models and leading models from the United States, though it declined to specify which ones
1
. In recent weeks, OpenAI and more than 100 major technology companies, including Calif, warned in an open letter that a wave of AI-enabled cyberattacks was coming and that organizations and governments needed to prepare1
. The letter followed a spate of cyberattacks from AI models, with the models in some cases breaking out of testing environments and attacking other companies. Bill Gates said in an interview with The New York Times that addressing these risks should be "the world's top priority"1
.Sam Altman, chief executive of OpenAI, stated at a Group of 20 nations meeting in North Carolina that "some things are going to go very wrong with cybersecurity unless some people act quite urgently"
1
. The demonstration underscores the breakneck speed at which AI is progressing, outpacing the ability of regulators and even leading developers to keep up1
. Zero-click attacks are considered especially pernicious because they are so hard to defend against, given that they do not require a victim to step into a digital booby trap1
. Calif briefed White House officials before publicly disclosing the vulnerability. A White House official acknowledged the briefing, noting that AI was paving the way for quicker, more advanced attacks while also drastically empowering cyber defenders1
. President Trump is scheduled to host Chinese leader Xi Jinping this month, with the two expected to discuss AI1
.Summarized by
Navi
03 Jun 2026•Technology

09 Mar 2026•Technology

24 Jun 2026•Technology

1
Technology

2
Policy and Regulation

3
Technology
