AI-Built WeWorm Hijacks WeChat Accounts via Unanswered Voice Calls

by priyanka.patel tech editor
AI-Built WeWorm Hijacks WeChat Accounts via Unanswered Voice Calls

A Palo Alto-based cybersecurity company named Calif used artificial intelligence to develop a self-replicating computer worm capable of hijacking accounts on WeChat, according to reports published on Sept. 8. The experimental threat, dubbed WeWorm, exploits a memory corruption bug in the software WeChat uses to handle voice calls. The zero-click attack takes over an account while the phone is still ringing, requiring no interaction from the victim. Even if the call is answered, victims hear nothing, and declining the call only ends that specific attempt while leaving open the possibility of repeat calls while the target sleeps.

AI-Built WeWorm Hijacks WeChat Accounts via Unanswered Calls

Chief Executive Thai Duong stated that his team, working alongside a mix of open-source and leading commercial AI models, found the vulnerability and wrote a remote code execution exploit in roughly two days, then spent another week building the worm. Calif noted that a project of this scale would once have taken a larger team months to complete, demonstrating how rapidly AI can accelerate the discovery and weaponization of software bugs.

Mechanics and Spread of the Worm

Once inside an account, an attacker gains full control to read and send messages, place calls, and act on the victim’s behalf. As a computer worm, the malware then works down the victim’s contact list to repeat the attack automatically. While the attacker must already appear on the victim’s friend list, Calif pointed out that compromising a single friend opens a path to everyone else. On its own, WeWorm does not take over the handset itself, though researchers indicated it could potentially lead to full device control if chained with separate Android and iOS bugs they have also reported.

AI-Built WeWorm Hijacks WeChat Accounts via Unanswered Voice Calls
Photo: The Next Web

The vast reach of the platform heightened concerns during the disclosure. Tencent reported 1.432 billion monthly active users across WeChat and its mainland version Weixin in the first quarter of 2026, making it China’s most-used mobile app. Beyond messaging, the platform houses payments, official accounts, and mini-programs used for shopping, bookings, and deliveries. Vinh Nguyen, a former chief data scientist at the U.S. National Security Agency, told The New York Times that an exponentially spreading worm could have reached hundreds of millions of devices within hours.

Response and Patch Deployment

Calif notified Tencent of the vulnerability on July 24. Tencent subsequently released updated WeChat versions for Android (8.0.77) and iOS (8.0.76) in August. Furthermore, Calif confirmed that the exploit had also been blocked on the server side, meaning users are not strictly required to update their apps to be protected.

AI-Built WeWorm Hijacks WeChat Accounts via Unanswered Voice Calls
Photo: PCMag

A Tencent spokesperson expressed gratitude to the researchers and confirmed that a server-side fix was deployed, noting there was no evidence that the vulnerability was ever exploited in real-world attacks. Calif similarly confirmed that no real-world attacks using the flaw had been observed, but urged industry leaders and governments to utilize AI models proactively to shore up defenses and secure critical software against similar zero-click threats.

Researchers Built an AI Worm That Hijacks WeChat by Calling You — You Don't Even Have to Answer — 1

You may also like