HeadlinesBriefing favicon HeadlinesBriefing.com

WeWorm: Zero-Click WeChat Worm Demo Released

Hacker News •
×

At Calif, our mission is to keep the Internet together by occasionally taking it apart. We believe everyone deserves a safe and secure Internet, including the people who cannot protect themselves. Today, we're releasing a demo of We Worm, the first zero-click worm to spread through We Chat calls across i OS and Android. This is the first installment in a series exploring zero-click attack surfaces in mobile messaging apps. We Chat is an "everything app" used by virtually everyone in China and by Chinese communities worldwide. Simply by calling a victim, We Worm can hijack their account and call their friends, spreading from phone to phone. If exploited, actors can compromise over a billion phones (or accounts), upending livelihoods and breaking communities worldwide.

We built a demo worm with three phones: The first Android phone, a Pixel 10a, is the attacker. We used it to call the second phone, an i Phone 17e, and exploited the bug to take over its We Chat while it was still ringing. We then used the compromised i Phone to call the third phone, another Pixel 10a, and took that one over the same way. Attacker calls victim, victim becomes attacker, victim calls the next victim. You can also watch individual Android and i OS RCE demos. Exploitation takes only seconds, and gives us full control of the We Chat account. We can read and send messages, make calls, and act on the victim's behalf.

The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds. Declining the call stops that attempt, but the attacker can simply try again later, for example, while the victim is asleep. This exploit requires the attacker to be on the victim's friend list. But that's not much of a barrier: an attacker can compromise one of your friends first and use their account to reach you. We Chat, like many messaging apps, gives trusted contacts more privileges. But once one contact is compromised, that trust works against you.

Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days. Building the worm took one more week. A worm at this scale used to be the kind of thing that took a larger team months. AI can already do most of the work here. We are publishing our findings to raise public awareness. We reported the We Chat bug to Tencent in July. As of today, they have mitigated our exploit for all users. We'd like to thank Tencent for a successful collaboration.