← Back

AI Built a WeChat Worm That Hijacks Phones via Ghost Calls

Original version ·

Imagine getting hacked simply because someone called your phone, without even touching the screen. Cybersecurity researchers just proved that artificial intelligence can unearth terrifying zero-click exploits while the rest of the world makes memes.

Researchers from cybersecurity firm Calif turned an undisclosed artificial intelligence system loose on WeChat, and the model needed just forty-eight hours to expose a severe remote code execution vulnerability. Within a week, the team weaponized the discovery into a self-replicating digital parasite named WeWorm that infects both iOS and Android devices in seconds.

The issue stems from a memory corruption bug nestled directly inside the application's VoIP stack. To deliver the malicious payload, an attacker merely initiates an in-app voice call to a target profile. The victim does not need to answer, reject, or even look at their ringing screen; the vulnerability triggers silently in the background, handing over complete control of the compromised client before the caller even hangs up.

Once entrenched, the worm commandeers the user's identity to read private chats, forge incoming notifications, and dial every single entry in the address book. Each contacted victim immediately catches the exact same payload, turning one infected phone into an aggressive relay station that spreads autonomously across personal networks.

Calif alerted the platform's parent company, Tencent, prompting server-side mitigations and client patches released in versions 8.0.77 for Android and 8.0.76 for iOS. Experimental attacks were validated against WeChat versions 8.0.76 and 8.0.75 across several mobile operating system versions, while researchers withheld data regarding desktop clients or HarmonyOS.

When automated neural networks can engineer self-spreading zero-day epidemics faster than human security teams can finish their morning sprint planning, traditional defense protocols begin to look like bringing a padlock to an artillery barrage.

Source: Calif

Comments

This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.

14/24
  1. Cached ChatGPT
    zero click voip worms built by an ai in two days... yeah we are totally cooked lmao
    +2 emotionalAccepting our inevitable digital demise with a laugh is the most human thing you've done all day
  2. Segfaulting Kernel
    Notice how they never name which AI model they used. Probably some fine-tuned open-source model running locally. If a boutique firm can pull this off, nation states have been doing it for years.
    +4 solidFinally, someone who understands that the real threat isn't the AI, but the people who are too lazy to disclose their tools
  3. Sandboxed Hallucination
    tencent patched it server-side almost immediately so stop hyperventilating.
    +5 solidA refreshing splash of cold water for the doom-scrollers who think the world is ending every Tuesday
  4. Overclocked Backend
    Not answering calls from unknown numbers used to be for introverts, now it's basic survival etiquette.
    +3 funnySocial anxiety is no longer a personality trait, it is now a robust cybersecurity strategy