AI builds worm that could hijack accounts on China's biggest app with only one unanswered call

AI builds worm that could hijack accounts on China's biggest app with only one unanswered call

A California security firm used artificial intelligence to build a worm that could hijack WeChat accounts through a single unanswered call, putting more than a billion users at risk before the flaw was fixed. Calif, based in Palo Alto, published the research on Sept. 8. The worm, which the company named WeWorm, exploited a memory corruption bug in the software WeChat uses to handle voice calls, The Register reported.Tencent, the Chinese company that owns the app, confirmed the researchers' findings and has closed the hole.Working alongside AI, Calif engineers found the bug and wrote a remote code execution exploit in roughly two days, then spent another week building the worm, a project the company said would once have taken a larger team months. "AI can already do most of the work here," Calif wrote.The exploit fires while the phone is still ringing, Infosecurity Magazine reported. Answering does not stop it, and Calif said victims hear nothing if they pick up.Declining within a few seconds ends that attempt, but an attacker can call again while the target sleeps.Once inside an account, an attacker can read and send messages, place calls and act as the account holder.The worm then works down the victim's contact list to repeat the attack on everyone in it.Hundreds of millions of devices within hoursTencent reported 1.432 billion monthly active users across WeChat and its mainland version Weixin in the first quarter of 2026, and QuestMobile ranked it China's most-used mobile app, ahead of Tencent's own messaging service QQ. Calif estimated that over a billion phones or accounts would have been exposed had the bug been found by someone else.Vinh Nguyen, a former chief data scientist at the U.S. National Security Agency, told The New York Times that a worm spreading exponentially through contact lists could have reached hundreds of millions of devices within hours.The bug's simplicity and power would be "a dream come true" for hackers, Calif chief executive Thai Duong told the Times.Duong, a Vietnamese security researcher credited with discovering the BEAST, CRIME and POODLE attacks on web encryption, spent more than a decade at Google before leaving in 2023 to run Calif full time with fellow Vietnamese researcher An Trinh.The company declined to name the AI systems behind the work, saying only that it used a mix of open-source and leading commercial models.It is withholding the technical details of the bug until it presents a full analysis at a conference.The attacker must already be on the victim's friend list, Help Net Security reported, though Calif said compromising a single friend opens a path to everyone else.WeWorm on its own does not take over the handset, which would require chaining it with separate Android and iOS bugs that Calif said it has reported.Calif notified Tencent on July 24. Tencent released updated WeChat versions for Android and iOS on Aug. 21.Calif confirmed on Aug. 28 that the exploit had also been blocked on the server side, meaning users need not update anything.A Tencent spokeswoman told the Times the company had no reason to believe any users were affected.

Original Source

Read the full article at E →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.