Researchers Built Zero-Click Worm to Hijack WeChat
A cybersecurity firm developed an AI-driven worm that compromised WeChat accounts without user interaction.
Updated on Sept. 23, 2026 in Cybersecurity

Live Poll
Do you trust the security of the messaging apps you use for daily communication?
Researchers at the Palo Alto-based firm Calif successfully created an AI-powered zero-click worm that hijacked WeChat accounts. The exploit allowed unauthorized access to private messages and contact lists on both iOS and Android platforms.
Why it matters
This development highlights the growing risks posed by artificial intelligence in creating automated cyber threats. The ability of the worm to propagate automatically between user contacts underscored significant vulnerabilities in messaging infrastructure.
The worm functioned by initiating an unanswered voice call, which allowed the software to execute an exploit within seconds. Tencent confirmed the vulnerability and implemented a server-side patch on August 28, 2026.
The players
Calif
This Palo Alto-based cybersecurity firm led the development of the AI-powered WeWorm exploit.
Tencent
This major technology conglomerate owns and operates the WeChat messaging platform.
The details
The WeWorm worm required zero interaction from victims, automatically spreading through user contact lists once an account was compromised. It granted attackers full access to chat histories, stored messages, and call logs across mobile operating systems.
Timeline
August 28, 2026: Tencent completed server-side remediation for the vulnerability.
September 2026: US and Chinese leaders are scheduled to meet to discuss AI hazards.
The Tech Race
This exploit signals a shift toward AI-automated cyberattacks that bypass traditional human-in-the-loop vulnerabilities. It follows a pattern where rapid technological capability breakthroughs force immediate global regulatory responses.
Users can maintain security by ensuring their applications are updated to the latest versions released by developers. While the specific vulnerability is patched, the threat of AI-driven worms reinforces the need to avoid answering calls from unrecognized numbers.
The takeaway
The successful deployment of this worm demonstrates that AI can significantly accelerate the creation of sophisticated digital exploits. Users should remain vigilant against unusual account activity and always maintain current software patches on their mobile devices.
Further reading
Learn more about the latest developments in Cybersecurity to understand global digital threats.
Source note: This article includes information reported by Dimsum Daily.
Live Poll
Do you trust the security of the messaging apps you use for daily communication?







