The WeWorm exploit dropped by Calif Research about a month ago is pretty nuts: the first zero-click worm for WeChat, capable of gaining full control over a user’s WeChat account and subsequently attacking everyone on that user’s contact list.
For those of you who have never heard of WeChat, it is China’s “everything app”: used for payments, messaging, and social media. It is also deeply embedded in China’s censorship and surveillance infrastructure. As such, gaining control over a user’s WeChat account gives an attacker a lot of power.
The exploit discovered by Calif researchers is about as bad as it gets. For the attack to work, the target must be on the “friend list” of the attacker, but the target is not required to answer the malicious call or interact with it in any way. While hanging up on the call blocks the exploit, an attacker can simply call again at a time when the user is unlikely to be awake. When account control is achieved, the compromised account can begin targeting all the users on the victim’s friend list. The attack can potentially be chained with other exploits to gain complete control over a victim’s iPhone or Android device.
Calif said they developed this attack with AI assistance, and they only published it after confirming that Tencent, the creator of WeChat, had fixed the exploit. There is no evidence that this exploit was used in the wild. But Calif says its AI found the bug and helped write the first remote-code-execution exploit in about two days, with the worm taking another week to build. That speed speaks to the new era of online security in the age of incredibly capable AI coding tools.
I recall someone pointing out that this incident might make the Chinese government reconsider how the country is deploying AI, since, as mentioned above, WeChat is a centrepiece of the country’s surveillance and censorship infrastructure.
