AI hacking tool builds worm that can infect China’s WeChat accounts with call: Report | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Saadet Gökce

09 September 2026Update: 09 September 2026

A small team of researchers has built an AI-assisted worm that can infect accounts on China’s WeChat social media and messaging platform with one call, according to a report by The New York Times.

WeChat is one of the world’s most widely used apps, with more than 1.4 billion monthly active users, almost all in China.

The worm, dubbed WeWorm, was developed by researchers at Calif, a Palo Alto-based security company.

Calif said it is the first known computer worm, a type of malicious software that can leap from machine to machine on its own, without human help, and spread across Apple’s iOS and Google’s Android operating systems without requiring users to click or tap anything.

Once an account is infected, the worm can compromise private messages and account control, and use saved contacts to spread further.

The attack exploits WeChat’s trust in phone numbers saved as friends, allowing the worm to spread from phone to phone.

Thai Duong, chief executive of Calif, said the vulnerability can be triggered when a user answers the call or lets it ring, while only declining it immediately prevents the attack.

Calif said the vulnerability could potentially allow an attacker to compromise a victim’s phone fully.

Tencent, WeChat’s owner, confirmed the vulnerability and said it fixed the issue after being contacted by Calif, according to the report that was published Tuesday.

A spokesperson said the company had no reason to believe that no users were affected and that no app update was required.

The bug’s simplicity and powerful abilities would be “a dream come true” for hackers, according to Duong.

The disclosure comes amid growing warnings about AI-enabled cyberattacks.

OpenAI and more than 100 major technology companies, including Calif, recently issued an open letter warning of a wave of AI-enabled cyberattacks.



Click Here For The Original Source.

——————————————————–

..........

.

.