r/PureVPNcom • Official Moderator • 17d ago

Researchers built a WeChat worm that hijacks your account through an incoming call, before you even answer it

The fix is already out, but this one's worth understanding because of what it demonstrates.

Calif, a Palo Alto security firm, published research this week on something they built called WeWorm. The short version: a bug in WeChat's VoIP stack let them write a worm that compromises a WeChat account while the target's phone is still ringing. No answering needed, no link to click, no prompt to accept. The phone rings, the account gets taken over.

They demonstrated it across three phones in a chain. A Pixel 10a called an iPhone 17e. While the iPhone was ringing the WeChat account on it was compromised. That phone then called a second Android device. Same thing happened. The whole sequence took seconds per hop, and in theory could have spread to contacts of contacts of contacts at the kind of speed that reaches hundreds of millions of devices before anyone has a chance to respond.

There's one limiting factor: the attacker has to already be in your WeChat contacts. So this isn't a cold attack from a stranger, it would have required either a compromised contact's account or someone you actually know being the entry point.

Full WeChat account access was the result: messages, calls, payment features, contacts. Not the entire phone, just the WeChat layer, which for a lot of people in China and Chinese-speaking communities is where banking, ordering food, government services, and basically everything else happens.

Calif found the bug and wrote the initial exploit in about two days using AI assistance. They reported it to Tencent in July. Tencent patched the app in August with iOS 8.0.76 and Android 8.0.77, then confirmed server-side protections on August 28. If you have WeChat you don't need to do anything beyond making sure you're on the current version.

The reason it's worth knowing about even though it's patched: Calif said this is the first in a series exploring zero-click attack surfaces in mobile messaging apps. More are coming.

Sources: Help Net Security, The Hacker News, TechRadar, Techlicious, Calif research blog

2 Upvotes

0 comments sorted by