Skip to content

project

WeWorm

Proof-of-concept self-propagating worm built by Calif that spreads through WeChat voice calls to take over accounts and then call the victim's contacts.

Current clusters

security4 publishers

Researchers built a WeChat worm that hijacks accounts while the phone is still ringing

Calif's WeWorm abused a memory corruption bug in WeChat's VoIP stack to take over accounts on an iPhone 17e and two Pixel 10a handsets, and Tencent blocked it server-side on 28 August without publishing an advisory or a CVE.

Perspective Coverage

4 publishers
Builder
Builder 35%
Operator
Operator 48%
Investor
Investor 17%

Reality

Evidence42
Adoption68
Hype gap+34
Incentives72
Confidence60