HomeRisk ManagementsResearchers Develop WeChat Zero-Click Worm that Hijacks Phones through Calls

Researchers Develop WeChat Zero-Click Worm that Hijacks Phones through Calls

Published on

spot_img

A cybersecurity startup known as Calif, situated in Palo Alto, California, has recently made headlines with the development of a groundbreaking hacking tool named WeWorm. This innovative tool is capable of compromising both Android and iOS smartphones through the simplicity of a single incoming call. The implications of this technology raise significant concerns in the realm of cybersecurity, particularly regarding the vulnerabilities of widely used applications.

The WeWorm hacking tool takes advantage of remote code execution (RCE) vulnerabilities specifically found in WeChat, the widely popular Chinese super-app. This application is employed by millions for a variety of functions, including messaging, voice calls, and financial transactions. Researchers at Calif assert that WeWorm represents “the first zero-click worm to spread through WeChat calls across iOS and Android,” as detailed in a disclosure report issued on September 8.

To validate their findings, the team conducted tests using several devices, including Google Pixel 10a models and an iPhone 17e model. The results were alarming and indicate a new avenue for hackers to infiltrate personal devices without any user interaction.

### Discovery of Memory Corruption in WeChat’s VoIP Stack

The researchers identified the root of the RCE vulnerability within WeChat back in July. Their investigation employed a combination of large language models (LLMs), both open-weight and closed-source, developed by various US frontier labs. Although they have not disclosed the specific models employed during their research, they have consistently noted that the vulnerability centers on a memory corruption issue within the app’s voice-over-IP (VoIP) stack. This flaw leverages the privileges associated with WeChat’s trusted contacts when communicating, posing a significant risk to users.

Interestingly, after reporting this serious flaw to Tencent, the company that develops WeChat, the researchers faced consequences that included a temporary ban from the platform. Following this, Tencent confirmed that indeed, exploiting the vulnerability could lead to remote command execution. They swiftly released patched versions of the application for both Android (version 8.0.77) and iOS (version 8.0.76) to mitigate this risk.

In a remarkable display of efficiency, the researchers at Calif managed to develop working exploits for the vulnerable versions of the WeChat app within a mere two days. They subsequently integrated these exploits into the WeWorm hacking tool, completing the entire project within a week.

### WeWorm: Unprecedented Control via WeChat Calls

The capabilities of WeWorm are particularly troubling; once an individual’s WeChat account is hijacked, the attacker gains complete control. This includes the ability to read and send messages, make calls, and act as if they were the victim themselves. The Calif researchers articulated a distressing aspect of the exploit: “The victim does not need to answer the call or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds. Declining the call stops that attempt, but the attacker can simply try again later, for example, while the victim is asleep.”

Moreover, while the exploit necessitates that the attacker be on the victim’s friend list, this requirement is not as restrictive as it may seem. An attacker could first compromise one of the victim’s friends and use their account to reach the individual, effectively sidestepping this limitation. The implications are further compounded by the researchers’ assertion that, when combined with other existing vulnerabilities in both Android and iOS platforms, WeWorm could lead to total device control.

The Calif researchers concluded that the efficiency of developing a worm of this scale, which previously would have taken a significantly larger team several months, is now achievable through advancements in AI technologies. They emphasized that while AI can handle much of the technical workload, their team’s expertise was crucial in determining the strategic targeting of the vulnerabilities and ensuring safe testing methods.

In summary, the advent of tools like WeWorm epitomizes the evolving challenges in the cybersecurity landscape. As users rely increasingly on applications like WeChat for daily communications and transactions, the exposure to such vulnerabilities underscores the urgent need for robust security measures and continuous monitoring of software ecosystems. The implications of this exploration by Calif stand as both a warning and a rallying call for vigilance in an age where digital interactions are fraught with risk.

Source link

Latest articles

France’s Mistral AI Highlights Its European Focus While Facing Challenges

“Made in France” Can Only Get Mistral So Far in AI Race In recent developments...

Hackers Exploit Google CAPTCHA, WebDAV, and BNB Smart Chain to Distribute Credential-Stealing Malware

Multi-Stage Malware Operation Unveiled A complex malware operation has recently come to light, engaging multiple...

ChatGPT Vulnerability Allows Attackers to Access Gmail Data Across Accounts Through a Hidden Channel

Enhancing Data Security: Expert Insights on Container-Level Leak Prevention A recent discussion highlighted critical strategies...

It Was Simply Being Manipulated

Hidden AI Activity Creates Security Gaps That Traditional Controls Can't Detect In an era increasingly...

More like this

France’s Mistral AI Highlights Its European Focus While Facing Challenges

“Made in France” Can Only Get Mistral So Far in AI Race In recent developments...

Hackers Exploit Google CAPTCHA, WebDAV, and BNB Smart Chain to Distribute Credential-Stealing Malware

Multi-Stage Malware Operation Unveiled A complex malware operation has recently come to light, engaging multiple...

ChatGPT Vulnerability Allows Attackers to Access Gmail Data Across Accounts Through a Hidden Channel

Enhancing Data Security: Expert Insights on Container-Level Leak Prevention A recent discussion highlighted critical strategies...