A New Era of Cyber Attacks Threatens WeChat: AI-Driven "WeWorm" Takes Over Just by Ringing Your Phone

A New Era of Cyber Attacks Threatens WeChat: AI-Driven "WeWorm" Takes Over Just by Ringing Your Phone

A friend calls on the smartphone.

Just looking at the screen, you don't answer the call. You don't click on suspicious links or open files.

Yet, the attack has already succeeded—.

An experiment that challenges conventional cyber security wisdom was unveiled in September 2026.

The target was WeChat, a massive life infrastructure in China. The security company Calif, based in California, developed a proof-of-concept worm called "WeWorm" that exploited a vulnerability in WeChat's voice call feature, demonstrating that an account could be taken over before the recipient answered the call.

What drew further attention was its ability to self-propagate by calling the next friend from the infected account, crossing between Android and iPhone.

However, it is important to emphasize upfront.

This is not an incident where "1.4 billion people in China were infected."

Security researchers demonstrated the danger in a safe environment, and as far as confirmed, there is no evidence of large-scale exploitation in the real world. Researchers reported the vulnerability to Tencent before publication, and Tencent has implemented countermeasures.

Still, there is a reason why this research garnered global attention.

The core issue is not that "WeChat had a bug."

It is that AI is rapidly reducing the time and human cost needed to create advanced cyber attacks.


In China, WeChat is more than just an "app"

Understanding WeChat merely as a messaging app like LINE or WhatsApp would misjudge the magnitude of the current issue.

Weixin for mainland China and WeChat for overseas encompass a multitude of services on a single platform, including messaging, voice and video calls, payments, official corporate accounts, mini-programs, search, games, and videos.

According to Tencent, the combined monthly active users of Weixin and WeChat surpassed 1.4 billion in the first quarter of 2026.

In China, much of daily life, such as shopping and payments, booking stores, contacting companies, and conversing with colleagues, is completed within WeChat.

Therefore, a WeChat account means more than just an SNS account.

Even if the smartphone itself is not completely taken over, the damage is severe if messages are read and written, impersonation occurs, and calls are made to friends.

Thus, the issue presented is not only a vulnerability problem of a single app but also the risk of concentrating social functions on a massive platform.


An attack succeeds "even without answering the phone"

WeWorm exploited a memory corruption vulnerability in the part of WeChat that handles internet calls, known as VoIP.

In typical phishing attacks, the victim needs to click a link or open a malicious file.

However, in a "zero-click" attack, even that operation is unnecessary.

In the research team's experiment, the attack was executed while the target's smartphone was processing the incoming call on WeChat.

There is no need to answer the call.

There is no need to read messages.

There is no need to install anything.

The incoming call itself becomes the entry point for the attack.

Calif demonstrated making a WeChat call from an Android device to an iPhone, taking over the account on the iPhone, and then calling another Android device from that iPhone to compromise the next account.

This mechanism of "an infected device becoming the next attacker" is why WeWorm is called a worm.


Being a friend turns from "defense" to "attack means"

WeWorm has an important condition.

The attacker's WeChat account needed to be in the target's friend list.

At first glance, this seems like a significant limitation.

It's not that anyone can be infected just by receiving a call from a stranger.

However, in a self-propagating worm, this condition changes its meaning.

For example, if person A's account is compromised by some method.

Then the attacker can call person B, who is friends with person A, from person A's account.

If person B is compromised, it spreads to person B's friends next.

Normally, information like "contact from a friend" enhances safety.

However, the moment one person is compromised, that trust relationship itself becomes an asset for the attacker.

The "social graph" that SNS and messaging services have built over the years can become the propagation path for the worm.


Taking over a WeChat account is different from "hijacking the entire smartphone"

There is another important distinction to understand this news.

The central capability confirmed in the WeWorm experiment is "taking over a WeChat account."

According to researchers, after the compromise, it becomes possible to read and send messages, make calls, and act as the person.

However, it was not demonstrated that WeWorm alone could completely control the iPhone or Android device itself.

While combining with other OS vulnerabilities could lead to device-level attacks, it is necessary to distinguish between "attacks that hijack a WeChat account" and "attacks that hijack the entire smartphone."

In news and on SNS, expressions like "completely hacking a smartphone with a single call" are more likely to spread.

However, to understand the actual risk, it is important to separate what has been demonstrated from what is theoretically an extension.


The biggest shock is not that "AI attacked"

The most important aspect of this news is not that zero-click attacks have appeared for the first time.

Zero-click vulnerabilities have existed before and have been used in advanced spyware.

What was particularly noted this time was the development speed.

Calif stated that by working with AI, the actual work to discover the vulnerability and create the first remote code execution attack took about two days, and it took about another week to create the self-propagating worm.

However, these figures are explanations by the research team themselves and not benchmarks by an independent third party.

According to the published timeline, the research team recognized the issue on July 23, reported it to Tencent on July 24, completed the attack code for Android on July 30, for iOS on August 2, and the completed demo spanning Android and iOS was on August 11.

So it does not mean "everything was completed in 48 hours from discovery."

Still, the fact that AI is speeding up processes like code analysis, vulnerability candidate exploration, and attack code creation is a change that cannot be ignored by the security industry.


AI lowers the "barrier to entry for advanced attacks"

There has been a significant barrier to entry for advanced cyber attacks.

It requires specialized knowledge of OS mechanisms, programming languages, networks, memory management, cryptography, and reverse engineering.

Moreover, just discovering a vulnerability does not mean it can be immediately exploited.

There is a big gap between a bug that causes a crash and a vulnerability that can stably execute arbitrary code.

Reading a large amount of code.

Looking for abnormal behavior.

Guessing the cause.

Writing test code.

Failing.

Analyzing the results.

Writing code again.

Such trial and error have occupied much of cyber attack research.

AI has the potential to greatly increase this iterative speed.

Human experts judge goals and safe verification methods, while AI handles code analysis and trial and error in large quantities.

If this combination matures, tasks that previously required large specialized teams might be advanced by smaller groups.

This is not just a problem for criminals.

State agencies, companies, security researchers, and cybercriminal groups can all use the same AI technology.


If attackers use AI, defenders should use AI too

Viewing WeWorm solely as an "incident proving the danger of AI" only captures half the essence.

The researchers who discovered the vulnerability did not use it for actual attacks but reported it to Tencent.

According to Calif's published timeline, Tencent was notified on July 24, Android version 8.0.77 and iOS version 8.0.76 were released on August 21, and by August 28, the research team confirmed that the attack was also blocked on the server side.

Tencent explained to another media outlet that the fix was implemented on the server side, and no special operation was required on the user side. They also stated that there is no evidence that the issue was actually exploited or that users were harmed.

This shows that AI is not an "exclusive weapon for attackers."

If AI can quickly discover unknown vulnerabilities, companies might also be able to use AI to find the same vulnerabilities before releasing products.

In an era where attackers explore with AI 24/7, a defense system that relies on humans taking weeks for code review cannot keep up.

It's not AI versus humans, but

"attackers using AI" versus "defenders using AI"

that is likely to become a speed competition.


On social media, reactions of "too scary" and "look calmly" intersect

After the release of WeWorm, it became a topic on X, Reddit, and China's Weibo.

 

The part that was particularly easy to spread was, of course, "you can be hijacked even if you don't answer the phone."

On China's Weibo, users posted introductions like "Simply put, you can be hacked on WeChat without doing anything just by receiving a voice call."

At the same time, there were posts explaining that "it has already been fixed, so just update" and "it's a WeChat issue, not the smartphone OS itself," showing reactions trying to organize the actual impact range, not just fear.

Overseas security personnel focused on slightly different points.

Citizen Lab researcher John Scott-Railton highlighted this research on X as a sign that the balance between attackers and defenders is changing, warning of the potential increase in breaches of widely used services.

The WeWorm research team itself introduced on X the mechanism where an account is compromised just by receiving a call and spreads to the next friend. At the same time, they showed a stance that the purpose of the research is not to deepen the conflict between the US and China, but to cooperate in discovering and fixing vulnerabilities faster using AI.

On Reddit, there were posts organizing WeWorm as "fixed, but worth understanding what it demonstrated."

There, it was emphasized that it needs to be in the friend list, that WeChat account compromise and entire device compromise are separate, and that Tencent has already fixed it.

Thus, the reactions on social media are largely divided into two.

From the perspective of general users, the fear of "getting infected without doing anything."

From the perspective of security personnel, the concern of "how much AI can shorten the time to create attack code."

The latter may be more important in the long run.

However, note that these are discussions in individual posts and technical communities that can be confirmed, not surveys representing public opinion in China or worldwide.


The real fear is not "WeWorm itself"

WeWorm has already been countered.

At least the published attack cannot be executed as is on current WeChat users.

So, is this news already a thing of the past?

No, it is not.

Calif positions WeWorm as the first case in a series investigating zero-click attack surfaces in mobile messaging apps.

It's not just about calls.

Messaging apps automatically process large amounts of data even before users operate them.

Incoming call information.

Image thumbnails.

Audio data.

Videos.

Notifications.

Link previews.

Attachments.

While these features enhance convenience, they can also become entry points for zero-click attacks.

"Please don't click on suspicious URLs."

"Don't open unknown files."

Cybersecurity education has often relied on user behavior.

However, in zero-click attacks, the attack succeeds before the user takes the correct action.

It's a