WeWorm proves an unanswered WeChat call can hand over an account

Researchers built a zero-click worm, dubbed WeWorm, that takes over WeChat accounts through incoming calls before Tencent's August fix.

CSBadmin
2 Min Read

WeChat accounts can be stolen through a call the victim never answers, and a proof-of-concept worm now shows the attack crossing between iPhone and Android. Calif, the security firm behind the demo, traced the flaw to a memory corruption bug in WeChat’s VoIP handling that a contact can trigger just by dialing.

The takeover needs no interaction from the person being called. Picking up changes nothing, Calif says, since the caller hears silence while the exploit runs; declining only ends that attempt, and the attacker can redial at will. A hijacked account hands over messages, calls and payment features, and because the caller must already be a contact, each new victim extends the reach to their own contact lists. The chain in Calif’s demo started on Android, jumped to an iPhone mid-ring, then took a second Android phone.

Tencent patched the bug on August 21 with WeChat 8.0.77 for Android and 8.0.76 for iOS, weeks after Calif’s July disclosure. Exploit code has not been seen in the wild, and the researchers are withholding technical details to slow reverse engineering.

AI tools helped Calif build the cross-platform chain, The Register reported. WeChat and Weixin count 1.439 billion monthly users, making the contact-trust weakness a reminder that a single stolen account can unravel a whole network.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.