CTIPilot

WeWorm

tool · tool:weworm

Calif's AI-assisted proof-of-concept zero-click worm that hijacks WeChat accounts on Android and iOS via an incoming VoIP call, exploiting an undisclosed memory-corruption bug in WeChat's call-signaling stack; propagates hop-to-hop by abusing WeChat's saved-contact trust. Reported to Tencent 2026-07-24; client fixes Android 8.0.77 / iOS 8.0.76 shipped 2026-08-21 and a server-side block confirmed by Calif on 2026-08-28; disclosed 2026-09-08 (Calif, calif.io/research/weworm).

Coverage timeline
1
first 2026-09-08 → last 2026-09-09
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
research
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Execution TA0002

T1203Exploitation for Client Execution×1

Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.

Evidence: 2026-09-09/weworm-ai-zero-click-wechat-worm-account-takeover · ATT&CK page ↗

Story timeline

  1. 2026-09-09WeWorm: an AI-assisted zero-click worm demonstrates full WeChat account takeover on Android and iOS from a single unanswered call
    researchCalif builds a self-propagating zero-click WeChat worm with AI help in about nine days; Tencent fixed it before disclosure

Where this entity is cited

  • research1

Source distribution

  • calif.io1 (33%)
  • helpnetsecurity.com1 (33%)
  • thehackernews.com1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about WeWorm (1)

2026-09-09 · view entry permalink →

NOTABLENATOB2

WeWorm: an AI-assisted zero-click worm demonstrates full WeChat account takeover on Android and iOS from a single unanswered call

Calif, a US offensive-security research firm, published a working demonstration of WeWorm on 2026-09-08: a zero-click worm that takes over a WeChat account on Android or iOS through a single incoming voice or video call, exploiting a memory-corruption bug in WeChat's VoIP call-signaling stack (Calif is withholding the specific bug detail pending a conference talk) (Calif, 2026-09-08). The exploit fires while the call is still ringing and requires no answer and no interaction: "The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds" (Calif, 2026-09-08). The only prerequisite is that the caller already sits on the victim's WeChat contact list, and because WeChat grants saved contacts additional trust, a first compromised account can call and take over further contacts on its own: Calif demonstrated hop-to-hop propagation across three physical devices, each full takeover (read and send messages, place calls, act as the account owner) completing in seconds (Calif, 2026-09-08; Help Net Security, 2026-09-08).

The transferable finding is a capability data point, not an active threat. Calif states an AI-assisted workflow found the bug and produced the exploit fast, "Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days" (Help Net Security, 2026-09-08), with the self-propagating worm built in one further week, work it says a human team previously needed months for. This is responsibly-disclosed research, not in-the-wild activity: Calif reported the flaw to Tencent on 2026-07-24, Tencent shipped client fixes (Android 8.0.77, iOS 8.0.76) on 2026-08-21 and, per Calif, blocked the exploit on its servers for all users by 2026-08-28, requiring no user install (The Hacker News, 2026-09-08). No CVE has been assigned and Tencent has published no advisory: "Checks on 8 September found no CVE identifier for the flaw and no advisory on Tencent's security response site, which lists the latest announcement as April 2022" (The Hacker News, 2026-09-08), and Calif declined to say whether the underlying bug, versus its specific exploit, is fixed (The Hacker News, 2026-09-08).

The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds.

Calif 2026-09-08

Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days.

Help Net Security 2026-09-08

Checks on 8 September found no CVE identifier for the flaw and no advisory on Tencent's security response site, which lists the latest announcement as April 2022.

The Hacker News 2026-09-08
research09 Sep 17:52Zmulti-sourceOpen finding ↗