$ techbeacon▋
Malware

AI‑Powered Zero‑Click Worm Targets WeChat Calls on Android and iOS

AI‑Powered Zero‑Click Worm Targets WeChat Calls on Android and iOS

Security researchers have demonstrated a new zero‑click worm that can seize control of both Android and iOS smartphones simply by exploiting an incoming WeChat voice call, without any user interaction.

The malicious code is triggered the moment a call is received, allowing the payload to execute silently. By leveraging a blend of large‑language models and automated code‑generation tools, the team was able to craft an exploit that bypasses the usual sandbox protections on both platforms.

WeChat, with over a billion active users worldwide, has long been a focal point for cyber‑espionage due to its integration of messaging, payments and social features. Prior incidents have mostly involved phishing links or malicious attachments, making a call‑based, no‑click attack a notable escalation in threat complexity.

According to the researchers, the AI component was used to iterate on exploit code rapidly, testing variations against emulated device environments until a stable, cross‑platform payload emerged. This approach reduces the time and expertise traditionally required to develop sophisticated zero‑click exploits, potentially lowering the barrier for threat actors.

The worm can grant an attacker full device control, including access to contacts, messages, location data and, on Android, the ability to install additional applications. On iOS, the exploit appears to achieve a similar level of privilege escalation, a rare achievement given Apple’s tighter security model. Such capabilities raise concerns about large‑scale surveillance and data theft, especially in regions where WeChat is a primary communication channel.

Industry analysts have urged WeChat’s parent company, Tencent, to issue urgent patches and to improve its call‑handling sandbox. Meanwhile, mobile‑platform vendors are advised to strengthen verification of inbound call data and to monitor for anomalous behavior indicative of zero‑click activity. Users are recommended to keep their operating systems and apps up to date, and to limit unnecessary permissions for messaging applications. The findings were first reported by Infosecurity Magazine.

Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related