HeadlinesBriefing favicon HeadlinesBriefing.com

AI-Built Worm Hacked WeChat Accounts Rapidly

New York Times Top Stories •
×

A friend you haven’t heard from in a while suddenly calls. You don’t pick up, but in a matter of seconds, the damage is already done. The call wasn’t actually from an old companion looking to reconnect, but from a hacker who had hijacked that number. Worse, the assailant now secretly has control over your account, including access to your private messages, and is already using your number to reach your saved contacts and compromise them, too. Like a raging, highly contagious virus, the attack keeps spreading. Within hours, millions of people have suffered the same fate. A year ago, such a cyberattack might have sounded far-fetched to even the most paranoid digital experts, or at least like something only the world’s most elite spy agencies could have pulled off. Instead, because of advanced artificial intelligence models, a small team of researchers at Calif, a security company based in Palo Alto, Calif., recently built a hacking tool in a little more than a week that could run roughshod across We Chat, the social media and messaging platform ubiquitous in China.

"This bug is exceptional," said Thai Duong, the chief executive of Calif, which says it builds hacking tools not to sell them but to bolster cyberdefense. The bug’s simplicity and powerful abilities, he added, would be "a dream come true" for hackers. The attack is the latest — and one of the most alarming — demonstrations yet of the breakneck speed at which A.I. is progressing, outpacing the ability of regulators and even of leading developers to keep up. Calif said the attack, which it named We Worm, was the first known computer worm — a type of malicious software that can leap from machine to machine on its own absent human help — that could spread across Apple’s i OS and Google’s Android operating systems without needing a victim to click or tap on anything. So-called zero-click attacks are different, and far more lethal, than standard phishing emails and texts. They are considered especially pernicious because they are so hard to defend against, given that they do not require a victim to step into a digital booby trap. A spokeswoman for Tencent, the Chinese technology company that owns We Chat, confirmed the vulnerability and said that it had fixed the issue after being contacted by Calif. The company had no reason to believe the issue compromised security or affected any users, the spokeswoman said in a statement, adding that no app updates were required by customers. The discovery is still likely to fuel more concerns that advanced A.I. models could soon usher in a dystopian future that shatters core assumptions about digital security and, at least in the short term, delivers a major advantage to malicious hackers. Calif said it relied on a combination of open-source A.I. models and leading models from the United States, but it declined to specify which ones. In recent weeks, Open AI and more than 100 major technology companies, including Calif, warned in an open letter that a wave of A.I.-enabled cyberattacks was coming, and that organizations and governments needed to prepare. The letter followed a spate of cyberattacks from A.I. models, with the models in some cases breaking out of testing environments and attacking other companies. Bill Gates, the billionaire co-founder of Microsoft, said in an interview with The New York Times that addressing these risks should be “the world’s top priority.”“We have a big challenge in front of us,” Sam Altman, the chief executive of Open AI, said last week at a Group of 20 nations meeting in North Carolina. “Some things are going to go very wrong with cybersecurity unless some people act quite urgently.”In the We Worm attack, once a We Chat account was compromised, a hacker could have read and sent messages, made calls and controlled the victim’s account. Computer worms leverage software vulnerabilities that do not require clicking on a link or a file to automatically deploy their code across a network or the internet, allo...