A cybersecurity research team demonstrated how rapidly artificial intelligence is lowering the technical barriers to sophisticated cyberattacks by developing WeWorm, a self-propagating “zero-click” exploit targeting WeChat users on both iOS and Android devices. The attack exploited a memory-corruption vulnerability in WeChat’s internet-calling system and could compromise an account simply through an incoming call from an account already on the victim’s friend list; the victim did not need to answer or click anything. Once compromised, the account could automatically call its contacts and continue spreading. Researchers said AI helped discover the vulnerability and produce a remote-code-execution exploit in roughly two days, with the complete worm developed about a week later. Tencent was notified privately in July and mitigated the vulnerability before its public disclosure, and there is currently no evidence that the worm was maliciously deployed. The episode nevertheless demonstrates that AI could dramatically compress the time, manpower and expertise previously required to construct cyberweapons capable of spreading across enormous digital networks.
Key Takeaways
- Artificial intelligence substantially accelerated development of a sophisticated zero-click cyberattack, allowing a small research team to move from vulnerability discovery to a working remote-code-execution exploit and then a self-propagating worm in a remarkably short period.
- WeWorm presented an unusually serious threat because an incoming WeChat call from a compromised friend account could trigger the attack without the recipient answering, clicking a link or taking another affirmative action, after which the compromised account could automatically target additional contacts.
- Tencent mitigated this particular vulnerability before public disclosure, and no malicious exploitation has been reported, but the broader security problem remains: AI is rapidly making capabilities once associated with elite hackers and intelligence services accessible to much smaller and potentially less sophisticated actors.
In-Depth
The discovery of WeWorm should end any lingering assumption that advanced cyberwarfare will remain the exclusive province of governments, intelligence agencies and elite hacking teams. Researchers at Calif used artificial intelligence to identify a memory-corruption flaw in WeChat’s voice-over-IP system, develop a remote-code-execution exploit and construct a self-propagating worm in little more than a week. The result could compromise an account from an incoming call without requiring the victim to answer, click a link or otherwise cooperate.
Once an account was seized, the worm could use that trusted identity to call contacts and continue spreading across iPhones and Android devices. The attacker had to originate from an account already on the target’s friend list, but a successful compromise effectively supplied the trusted accounts needed for further propagation. Researchers warned that such a mechanism could potentially reach enormous numbers of users rapidly.
Tencent was privately notified in July and subsequently mitigated the vulnerability before the research became public. No evidence has emerged that WeWorm was deployed maliciously in the wild.
The larger issue is the collapsing cost of sophisticated cyber capability. AI did not create insecure software, but it can dramatically accelerate the discovery, exploitation and automation of vulnerabilities that previously demanded substantial expertise and manpower. That creates a national-security challenge regulators cannot solve simply by restricting American AI development. Washington must ensure American defenders, technology companies and intelligence services retain access to the strongest tools available. Slowing responsible domestic development while hostile states and criminal organizations race ahead would leave Americans less secure, not more.

