BackUS Researchers Demonstrate AI-Powered Exploit for WeChat Accounts
US Researchers Demonstrate AI-Powered Exploit for WeChat Accounts
Tech
SCMP Tech2 hours agoTech1 min readChina

US Researchers Demonstrate AI-Powered Exploit for WeChat Accounts

Calif security firm discovers vulnerability allowing account hijack via unanswered voice calls, patched by Tencent.

Quick Look

  • US security firm Calif demonstrated an AI-driven exploit called WeWorm that can hijack WeChat accounts via unanswered voice calls.
  • Tencent deployed a server-side fix in August after being alerted by the researchers.

AI-generated summary

Why It Matters

US security firm Calif identified a vulnerability in Tencent's WeChat app that allowed exploitation via unanswered voice calls.

Font size

US cybersecurity researchers have demonstrated how artificial intelligence could help hijack WeChat accounts via unanswered voice calls, intensifying concerns about AI-driven cyber threats and prompting renewed calls for bilateral cooperation between the United States and China.

US security firm Calif said on Tuesday that its AI system identified a critical flaw in Tencent Holdings’ widely used messaging and payments app in July. In just a little over a week, researchers developed WeWorm – an experimental exploit that could allow an attacker to take full control of a target’s WeChat account via a simple voice call, without the victim ever picking up the phone.

Tencent patched the bug in late August, according to Calif, which alerted the Chinese tech giant.

A Tencent spokesperson confirmed on Wednesday that a server-side fix was deployed, requiring no user action, and noted there was no evidence that the vulnerability was ever exploited in the wild. Tencent added that it was “grateful to the researchers for bringing this to our attention and working with us”.

The experiment underscores the speed at which AI is accelerating cyber threats. A worm of this complexity previously required months of work from larger engineering teams, but Calif researchers noted that “AI can already do most of the work here”.

The findings left some analysts alarmed.

Open Questions

  • Was the vulnerability ever attempted to be exploited by malicious actors?
  • What specific AI tools were used to build WeWorm?

Related Topics

This article was originally published by SCMP Tech.

Related Stories

Liaoning explores the new path of "artificial intelligence + 12345 hotline" to promote the digital and intelligent transformation of government services
Tech·

Liaoning explores the new path of "artificial intelligence + 12345 hotline" to promote the digital and intelligent transformation of government services

Liaoning Provincial Data and Government Services Bureau relies on the Artificial Intelligence + 12345 Hotline Joint Laboratory to build a "government, industry, academia, research and application" collaborative mechanism, adhere to compliance first and localized deployment, promote the implementation of large government model applications and achieve cross-provincial export, and create a core base for digital government construction.

中国新闻网
4 min read
2026 International Automotive Intelligent Cockpit Conference opens in Xiangcheng, Suzhou
Tech·

2026 International Automotive Intelligent Cockpit Conference opens in Xiangcheng, Suzhou

The 2026 International Automotive Intelligent Cockpit Conference opened in Xiangcheng, Suzhou on the 8th, with the theme of "Global AI·Active Interaction-Intelligent Agents Define the Next-Generation Cockpit New Ecosystem". More than a thousand representatives from global government, industry, academia and research attended the conference to explore cutting-edge issues such as the upgrading of the smart cockpit industry, AI native bases and in-depth integration of cabin driving.

中国新闻网
3 min read
More on this topicwechat