AI helped build a WeChat worm that spreads through phone calls
Newsroom / Security and Privacy desk
A messaging platform with more than a billion accounts normally represents years of adversarial research before anyone produces a working exploit chain. Calif Research compressed that into about nine days of work.
What the worm does
Calif published WeWorm on September 8, 2026. The attack begins with a phone call from someone already on the victim’s WeChat friend list. The victim does not need to answer the call or interact with the phone at all. Within seconds the account is taken over, giving the attacker the ability to read and send messages, place calls, and act on the victim’s behalf. The worm then places calls to that person’s contacts and repeats the cycle.
The exploit works across iOS and Android alike. Calif estimates the technique could compromise over a billion phones or accounts.
The timeline is the finding
Working with AI models, the team found the remote code execution flaw and wrote the first exploit in about two days. Building the self-propagating worm took one more week.
That compression is what separates this from an ordinary vulnerability disclosure. The bug itself will be forgotten. The schedule will not.
Where it stands now
Tencent shipped patched clients on August 21, 2026, and Calif confirmed on August 28 that the exploit was blocked on Tencent’s servers as well. Users running current versions are not exposed.
The open question is what the same schedule looks like when applied to other large messaging platforms, and whether defensive research can move at a comparable pace now that it has access to the same tools.
Sources
ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.