By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Felly ViralFelly ViralFelly Viral
Notification Show More
Font ResizerAa
  • Home
  • Technology
    TechnologyShow More
    Antioch raises $32m to test robots in simulation before they touch hardware
    September 10, 2026
    Another big James Talarico interview is punted to YouTube due to FCC threats
    September 10, 2026
    The iPhone Duo’s hardware doesn’t look special, but its software might be
    September 10, 2026
    OpenAI’s Bubeck denies trying to cut Anthropic mathematician from credit
    September 10, 2026
    Why the current tech backlash feels different
    September 10, 2026
  • Sports
  • World News
    World NewsShow More
    The Houthis are testing the limits of Saudi restraint
    September 10, 2026
    IAEA accuses Iran of ‘noncompliance’: Why, and what now?
    September 10, 2026
    Hong Kong court rules Dow Jones tried to stop journalist taking union role
    September 10, 2026
    How Ukraine’s deepest attack in Russia, on Arctic gas, signals new reach
    September 10, 2026
    Drone video shows aftermath of deadly ferry fire off the Philippines
    September 10, 2026
  • Politics
    PoliticsShow More
    Air traffic chaos and compensation: 'Shutdown cost us more than £1,000'
    September 10, 2026
    Air traffic chaos and compensation: 'Shutdown cost us more than £1,000'
    September 10, 2026
    Lindy Cameron appointed first ever female head of UK Foreign Office
    September 10, 2026
    Labour shifts on Israel – but what difference will it make? | podcast
    September 10, 2026
    MPs on both sides urge Commons not to take ‘extraordinary risk’ of forcing through assisted dying bill
    September 10, 2026
  • Science
  • Entertainment
    EntertainmentShow More
    Hollywood Shifts Strategy as Cross-Studio Streaming Bundles and Expanded Theatrical Windows Take Hold
    September 10, 2026
    Suno releases its first AI music model made with record industry help
    September 9, 2026
    Covenant leaves stealth with Anthem and factories in three countries
    September 9, 2026
    Alex Gibney’s Musk documentary premieres in Venice with an AI-simulated interview
    September 9, 2026
    Doyle: Waardah the one to beat in the Park Hill
    September 9, 2026
  • Contact
Reading: Researchers used AI to build a WeChat worm that spreads through phone calls
Share
Font ResizerAa
Felly ViralFelly Viral
  • Entertainment
  • Science
  • Technology
Search
  • Home
    • Home News
    • Home 2
    • Home 3
    • Home 4
    • Home 5
  • Categories
    • Technology
    • Entertainment
    • Science
    • Health
  • Bookmarks
    • Customize Interests
    • My Bookmarks
  • More Foxiz
    • Blog Index
    • Sitemap
Have an existing account? Sign In
Follow US
Felly Viral > Blog > Technology > Researchers used AI to build a WeChat worm that spreads through phone calls
Technology

Researchers used AI to build a WeChat worm that spreads through phone calls

admin
Last updated: September 10, 2026 12:19 pm
admin Published September 10, 2026
Share
SHARE
September 10, 2026 at 12:19 pmIn: Technology

Credit: © Prykhodov / Getty Images via Canva.com Researchers at Calif, a Palo Alto security company, say they used AI to build a worm that spreads through WeChat calls. It takes over an account while the phone is still ringing. It then uses that account to call the victim’s contacts and repeat the trick. Tencent, which owns WeChat, has confirmed the flaw and says it has fixed it.

It says it has no reason to believe any users were affected. Dustin Volz of The New York Times reported the attack on 8 September. Calif published its own write-up the same day and named the worm WeWorm. It calls it the first zero-click worm to spread through WeChat calls on both iOS and Android.

There are no reports of anyone using it in a real attack. TNW has not tested the exploit, and Calif has withheld the technical details. The reach is what makes it serious. WeChat and Weixin, its Chinese version, had 1.439bn combined monthly users on 30 June, according to Tencent’s second-quarter results.

For most of those people the account is more than a chat app. It also holds payments, official accounts and the mini programs that run inside WeChat. How the attack works The attacker has to be on the victim’s friend list, and then simply calls. The victim does not need to answer.

If they do pick up, they hear nothing and the exploit still works. Declining the call stops that attempt, but the attacker can try again later, for example while the victim sleeps. The friend-list condition is weaker than it sounds. An attacker who controls one account can use it to reach everyone that account trusts.

WeChat gives contacts extra privileges, and Calif says that is the weakness. “Once one contact is compromised, that trust works against you,” the company wrote. A successful call gives full control of the account. The attacker can read and send messages, make calls and act as the owner. Calif says the flaw is a memory corruption bug in WeChat’s internet calling stack.

It adds that other Android and iOS bugs it has reported could extend the attack to the whole phone. It has not published that chain. Two days, or three weeks Calif says its team, working with AI, found the bug and wrote the first exploit in about two days. Building the worm took one more week. “This bug is exceptional,” Thai Duong, its chief executive, told the Times.

Calif told the paper it used a mix of open-source and leading US models, but declined to name them. Calif’s own timeline runs longer. The team learned of the bug on 23 July and finished the first Android exploit on 30 July. The demo worm was ready on 11 August.

Swati Khandelwal of The Hacker News spotted the gap. It noted that the post does not say whether the shorter figures count only working time. People still did much of the work. Duong told the Times that his team had to “babysit the entire process” to get a working worm.

Calif also told The Hacker News that it wrote a set of skills to steer an AI through the attack surfaces of messaging apps. The AI found this flaw using them. The pattern is familiar from this year. In May, Google said it had found and stopped the first AI-generated zero-day exploit.

In August, an AI agent built a working exploit for a macOS flaw in four hours. The WeChat worm adds the part that spreads by itself. What Tencent says, and what it has not published A Tencent spokeswoman confirmed the vulnerability to the Times. She said the company fixed it after Calif got in touch.

She also said Tencent had no reason to believe the flaw compromised security or affected any users. Customers did not need to update the app, she said. Calif’s timeline fills in the rest. It reported the bug on 24 July, and says it then lost access to its own WeChat accounts from 25 to 28 July.

Tencent shipped Android version 8.0.77 and iOS version 8.0.76 on 21 August. Calif confirmed a server-side block for all users on 28 August. On 4 September, Tencent confirmed that an attacker could use the flaw to run commands remotely. Calif thanked Tencent for “a successful collaboration” in its post.

The public record is thinner. The Hacker News found no CVE identifier for the flaw. It also found no advisory on Tencent’s security response site, where the latest notice dates from April 2022. The release notes called the update bug fixes and nothing more.

Calif told the outlet it tested Android 8.0.76 and iOS 8.0.75. It declined to say whether it tested the HarmonyOS, Windows, Mac or Linux clients. Asked whether Tencent fixed the underlying flaw or only blocked the exploit, it said it could not comment. A user on another build cannot tell whether they faced any risk.

What Europe’s rules require From 11 September, the EU’s Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities in their products. They must send an early warning within 24 hours and a notification within 72 hours. A final report follows within 14 days of a fix. A national incident response team receives each report, and ENISA, the EU cybersecurity agency, gets it at the same time.

That duty covers flaws that attackers are known to exploit. Nobody has said anyone exploited this one. A wider duty in the regulation’s text starts on 11 December 2027. From then, manufacturers must publish information about vulnerabilities they have fixed.

That includes a description, the affected products, the severity and how users can protect themselves. Why the timing matters Calif briefed White House officials before it went public, and an official acknowledged the briefing to the Times. President Trump is due to host Xi Jinping this month. The US plans to raise AI-directed cyberattacks with China at that meeting.

The warnings have been piling up. According to the Times, Calif was among more than 100 organisations that signed an open letter in August about coming AI-enabled attacks. Days later, the chair of the Financial Stability Board told G20 finance ministers that AI-driven attacks were the most immediate threat to the financial system. Calif draws a different lesson from its own work. “The easy reaction is to blame AI and try to curtail its further development,” the company wrote, calling that the wrong lesson.

Its case is that AI lets defenders find and fix flaws faster than attackers can use them. Vinh Nguyen, a former chief data scientist at the National Security Agency, reviewed the research before publication. He told the Times it was one of the most troubling attacks he had seen. “Within hours, you could reach hundreds of millions of devices,” he said. Calif says WeWorm is the first in a series on messaging apps, with the full analysis due at a conference.

Until then, the public evidence is a three-phone demo and a timeline. Whether Tencent fixed the flaw itself, or only blocked the exploit, is the question neither company has yet answered in public.

You Might Also Like

China’s answer to ASML runs on Zeiss lenses, Financial Times reports

Lawsuit: Amazon refused to give pregnant workers bathroom breaks and chairs

Broad flexible smartphone from Chinese tech giant boasts superior performance over rival model

Apple’s iPhone 18 Pro has variable aperture, and no Siri AI in Europe

It’s the year of smartphone price hikes

Share This Article
Facebook Twitter Email Print
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

What's Hot

Badenoch accuses Burnham of kicking defence spending into the long grass

Zack Polanski says he'll run for former PM Starmer's seat in by-election

How significant is the Yemeni government’s military gains against Houthis?

Aviation faces hotter, stormier skies – and passengers might have to accept more disruption

Yemen’s war is back: A new battle for Sanaa and the Red Sea

‘Rhetoric differs’: How the UK’s relationship with Israel took a downturn

Categories

Business

71 Articles

Politics

267 Articles
- Advertisement -
Ad image

Categories

  • ES Money
  • U.K News
  • The Escapist
  • Insider
  • Science
  • Technology
  • LifeStyle
  • Marketing

About US

We influence 20 million users and is the number one business and technology news network on the planet.

Subscribe US

Subscribe to our newsletter to get our newest articles instantly!

© Foxiz News Network. Ruby Design Company. All Rights Reserved.

Powered by
►
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
►
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
►
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
►
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
►
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by
Welcome Back!

Sign in to your account