Researchers built a zero-click worm, dubbed WeWorm, that takes over WeChat accounts through incoming calls before Tencent's August fix.