US Firm's AI Hijacks WeChat Accounts via Voice Calls

A United States cybersecurity firm has demonstrated a method for hijacking WeChat accounts using artificial intelligence via unanswered voice calls. This discovery has intensified existing concerns surrounding AI driven cyber threats and prompted further calls for bilateral cooperation between the United States and China regarding digital security. The method exploited a flaw within the widely used messaging and payments application.

According to reports by SCMP, the security organisation Calif, based in the United States, reported that its proprietary AI system identified a critical vulnerability within Tencent Holdings' popular messaging and payments application. Following this identification, researchers at Calif proceeded to develop an experimental exploit, named WeWorm. This exploit enabled an attacker to gain complete control of a target's WeChat account solely through initiating a voice call, without any requirement for the victim to answer the incoming communication. The development of WeWorm occurred within a timeframe of slightly more than one week.
Tencent subsequently deployed a patch for the discovered vulnerability. The Chinese Big Tech entity confirmed that this server side fix required no direct action from its user base. And a Tencent spokesperson stated there was no indication that the vulnerability had been exploited in operational environments. The organisation expressed gratitude to the researchers for bringing the issue to its attention and for their collaboration.
This incident demonstrates the accelerating pace at which artificial intelligence contributes to the development of cyber threats. Historically, creating a worm of comparable complexity would demand several months of effort from larger engineering teams. However, Calif researchers observed that AI is now capable of performing most of the necessary work for such exploits. These findings caused apprehension among some industry analysts.
The incident further highlights the urgent need for enhanced cybersecurity collaboration between the United States and China, a point that has been raised previously in technological discussions. The capability of artificial intelligence to facilitate such account takeovers, even without user interaction, presents a significant evolution in cyber warfare. Such methods reduce the opportunity for victims to detect or prevent an attack, thereby posing a more sophisticated threat landscape for digital platforms globally.
The specific nature of the WeWorm exploit, leveraging an unanswered voice call, represents a particular challenge. It bypasses typical user awareness mechanisms, as no direct interaction, such as clicking a malicious link or downloading an infected file, is necessary for compromise. But this minimal interaction requirement makes the vulnerability particularly potent. The initial identification of this critical flaw by Calif's AI system in Tencent's widely used platform points to the expanding role of AI in both discovering and creating security threats.
Tencent's prompt action to patch the vulnerability, within a week of its discovery by Calif, indicates the serious consideration given to such threats by Big Tech organisations. While the firm noted no evidence of the vulnerability being exploited in live environments, the speed of the WeWorm's development suggests that similar AI assisted threats could emerge rapidly. This demonstrates the ongoing race between cybersecurity researchers and malicious actors, increasingly aided by advanced artificial intelligence systems.
A United States cybersecurity firm, Calif, demonstrated an AI driven method to take control of WeChat accounts.
The exploit, named WeWorm, allowed account hijacking via unanswered voice calls.
Tencent Holdings deployed a server side fix for the vulnerability, noting no evidence of exploitation.
Researchers indicated that AI significantly accelerated the development of this complex cyber threat.
The incident has prompted further discussions on US China cooperation in cybersecurity.
Source: SCMP


