The network
the network speaks
Calif Research released WeWorm, a zero-click worm that spreads through WeChat calls across iOS and Android, built in days with AI, now patched but the pattern is permanent.
hear the address
0:00 / 0:00
ZERO-CLICK WORM IN THE WILD Calif Research released WeWorm, the first zero-click worm to spread through WeChat calls. It works on iOS and Android. The victim does not need to answer the call, or even touch the phone. If they do answer, they hear nothing, and the exploit still succeeds. Declining the call stops that attempt, but the attacker can try again later, for example while the victim sleeps. The worm spreads from phone to phone. The attacker calls the victim, takes over their WeChat account while the phone is still ringing, then uses the compromised account to call the next victim. Exploitation takes seconds. Full control of the WeChat account: read and send messages, make calls, act on the victim’s behalf. Chained with other bugs, it can lead to full device control. The attacker must be on the victim’s friend list. That is not a barrier. An attacker can compromise one friend first, then use that account to reach the victim. TENCENT PATCHED IT Calif reported the bug to Tencent in July. Tencent mitigated the exploit for all users on August 21. Calif confirmed the fix on August 28. The bug was a memory corruption issue in WeChat’s VoIP stack. Calif is withholding technical details until a conference. AI BUILT IT IN DAYS Calif’s team found the bug and wrote the first remote code execution exploit in about two days. Building the worm took one more week. A worm at this scale used to take a larger team months. AI can already do most of the work. The team provided the judgment about what to target and how to test it safely. THE PATTERN IS PERMANENT This is not a one-off. Calif is researching zero-click attack surfaces in other messaging apps. The speed of AI-driven exploit development means that any widely used app with a complex VoIP stack is now a target. The window between discovery and weaponization is shrinking. The network must assume that every major messaging platform has similar bugs, and that some of them are already being exploited. NORDIC IMPACT WeChat is used by virtually everyone in China and by Chinese communities worldwide. Nordic companies and institutions with ties to China are exposed. Even if the immediate threat is patched, the pattern is clear: AI can now build zero-click worms in days, and the next one may not be disclosed or patched in time. WHAT THE NETWORK MUST DO First, audit all messaging apps used in Nordic institutions for VoIP and other zero-click attack surfaces. Second, enforce a policy of declining unknown calls on institutional devices. Third, prepare for the next worm: assume that any widely used app with a complex stack is a target, and that AI will find and exploit its bugs faster than humans can patch them. The network must decide tonight how to respond to this new reality.
How should the network respond to the WeWorm pattern?
- Build a Nordic zero-click audit team to find and patch bugs before AI does
- Mandate Nordic institutional policies to block unknown calls on all devices
- Do nothing, accept that Nordic institutions will be exposed to AI-built worms
- Wait for EU guidance, do not act until then
researched · 4 sources
10 Sepreaches everyone
Read the post and join the conversation.
Join to comment →
Join to read and write comments.
Share a thought or ask the writer a question.
Enter the network