Researchers Build AI-Powered WeChat Worm That Spreads Through Calls
Security researchers at Palo Alto-based Calif say they used AI tools to build a self-spreading worm capable of taking over WeChat accounts through incoming calls without requiring the victim to answer.
The researchers named the proof-of-concept WeWorm and described it as the first zero-click worm capable of spreading through WeChat calls on both Android and iOS. Tencent has confirmed the vulnerability and says it has fixed the issue, with no evidence that users were affected.
Attack Worked While the Phone Was Ringing
The attacker first needed to be on the victim’s WeChat friend list.
From there, the attacker could place a call to the targeted account. Calif said the victim did not need to answer for the exploit to work. If successful, the attacker could gain control of the account and then use it to call additional contacts, allowing the worm to spread.
Declining the call stopped that individual attempt.
Calif said a compromised account could allow an attacker to read and send messages, make calls, and act as the account owner.
The company attributed the vulnerability to a memory corruption flaw in WeChat’s internet calling system.
AI Helped Researchers Develop the Exploit
Calif said AI played a major role in finding the vulnerability and developing the exploit.
Its researchers told The New York Times that an initial exploit took about two days of active work, with another week spent developing the worm.
However, Calif’s published timeline covers a longer period. The company first learned about the vulnerability on July 23, completed an Android exploit on July 30, and had the demo worm ready by August 11.
Calif said human researchers still needed to closely supervise the AI throughout the process.
The company used a mixture of open-source and major US AI models but did not disclose which specific models were involved.
Tencent Says the Vulnerability Is Fixed
Tencent confirmed the vulnerability after Calif reported it on July 24.
According to Calif, Tencent later released WeChat 8.0.77 for Android and 8.0.76 for iOS on August 21 before introducing a server-side block for all users on August 28.
Tencent subsequently confirmed that the vulnerability could allow remote command execution, according to Calif.
The company told The New York Times it had no reason to believe the flaw had been exploited or had compromised any users. Tencent also said users did not need to manually update the app because it had implemented protections on its side.
No CVE identifier or detailed public security advisory has been issued for the vulnerability.
Potential Reach Was Significant
WeChat and its Chinese version, Weixin, had around 1.439 billion combined monthly active users as of June 30, according to Tencent.
That scale made the vulnerability particularly concerning because WeChat accounts are commonly connected to messaging, payments, official accounts and mini programs.
Calif has not released the technical details required to reproduce the exploit, and there are currently no reports of WeWorm being used in a real-world attack.
The company said the project is part of a broader series of research into messaging applications, with a more detailed technical analysis expected to be presented later.
The post Researchers Build AI-Powered WeChat Worm That Spreads Through Calls appeared first on ProPakistani.



