Skip to content
Hacker News front page

WeWorm: The first zero-click worm that spreads through WeChat calls

WeWorm: Zero-Click WeChat Worm

Calif built a demo worm that hijacks WeChat accounts over VoIP calls on iOS and Android, no user interaction needed. An attacker calls a friend, takes over their account while the phone is still ringing, then uses that account to call the next victim. AI helped find the bug and write the RCE exploit in about two days; the full worm took one more week. Tencent mitigated the issue server-side for all users by late August. Technical details are withheld for a future conference talk.

Read the original ↗Export Markdown