Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology6 min read

Experts build WeChat worm able to spread across millions of iPhone and Android devices via phone calls | TechRadar

Your phone rings, and you're infected Discover insights about experts build wechat worm able to spread across millions of iphone and android devices via phone c

TechnologyInnovationBest PracticesGuideTutorial
Experts build WeChat worm able to spread across millions of iPhone and Android devices via phone calls | TechRadar
Listen to Article
0:00
0:00
0:00

Experts build We Chat worm able to spread across millions of i Phone and Android devices via phone calls | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

Experts build We Chat worm able to spread across millions of i Phone and Android devices via phone calls

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Calif researchers found a zero‑click We Chat Vo IP flaw enabling account takeover via calls

“We Worm” spreads through ringing calls; victims need not answer to be compromised

Tencent patched in Android 8.0.77 and i OS 8.0.76; no exploitation seen in the wild

Security researchers have found a flaw in We Chat which allows malicious actors to take over people’s accounts on both Android and i OS devices - but what makes this flaw stand out is the fact that it’s a zero-click bug - victims need not do a thing to be compromised.

We Chat is a “super-app”, allegedly used by roughly 1.4 billion people, and is especially popular in China. It started as a communications app, letting users send messages, and make voice and video calls, and has evolved to function as a social network, allowing users to share photos and videos, as well as a payment app through which users can transfer money, pay for things, order food, book taxis, and even access government and business services.

Security researchers from Calif have now disclosed finding a ‘memory corruption’ issue in We Chat's Vo IP stack. For now, they decided not to share the technical details, and to instead demonstrate the flaw “at an upcoming conference.” To that end, they built a worm called We Worm, capable of taking over target We Chat accounts and spread through phone calls made via the app.

In practice, it works remarkably simple: an attacker uses We Chat to call a person they have in their contacts list (this is a prerequisite). They can use both an Android and an i OS device, and can call anyone, regardless of the model or the OS they’re using. As soon as the phone starts ringing, We Worm gets to work, “worming” its way into the victim’s device.

The victim does not even need to answer the phone - having it ring is enough. If they answer, they’ll hear nothing but silence, yet the worm will continue operating. If they decline the call, the attack stops, but this is hardly a mitigation - the attacker can simply call again while the victim is asleep (or otherwise away from their device).

A dangerous Zoom screen-sharing bug could have let hackers hijack other devices on a call

Android users beware — if you own one of these budget smartphones, your device could be hacked with a simple video call

New Whats App phishing campaign allows for remote access from a single business document

Within a few seconds, the attacker will have access to the victim’s We Chat account, including their messages, contacts list, and virtually anything else found in the app. What makes this bug particularly worrisome on the surface is the fact that We Chat can be used to transfer money and pay for things, but We Chat Pay has additional authentication and risk controls designed to prevent that from happening.

The good news is that there is no evidence of this flaw being exploited in the wild. The bad news is that this is not the first zero-click flaw found in modern-day smartphones, and most likely will not be the last one.

Calif said it responsibly disclosed its findings to We Chat’s parent company Tencent, who came back with a patch. Versions 8.0.77 for Android and 8.0.76 for i OS have apparently solved the problem, although

Tencent did not list any details in its patch notes, simply saying the version brought “bug fixes”, but in a statement shared with The Hacker News, it said the exploit has been “mitigated for all users”, and that it was applied server-side - users need not install anything, aside from the patch.

It’s also worth mentioning that We Chat has apps for Harmony OS, Windows, Mac, and Linux. However, it would appear that Calif did not test those, and Tencent did not include them in its patch. The researchers did say that they would be looking into this same flaw in other products, too:

“This specific We Chat bug is one instance of the many unconventional attack surfaces that are present across many messaging apps,” they said. “We're conducting more of this research across other apps and attack surfaces, while working with app developers on attack surface reduction. This may take an industry-wide effort, since some of it depends on the platform owners. Once that work is further along, we'll share our progress, including the technical details of this We Chat bug.”

➡️ Read our full guide to the best antivirus

  1. Best overall: Bitdefender Total Security
  2. Best for families: Norton 360 with Life Lock
  3. Best for mobile: Mc Afee Mobile Security

Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, Io T, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Despite spending billions on data centers and AI, US government report finds Amazon workers are using food stamps more than ever

AI data centers have a hidden cost few highlighted: A $200 billion insurance price tag that consumers will end up paying

i Phone price hikes — here's the full list of price rises for every model

'We wish you’d die of a slow death': US officials wedged between data center giants and local communities come under intense pressure over rural land markets

Russia is still trying to make its Starlink competitor work — 32 new Rassvet satellites launched into orbit, but it still isn't enough to operate fully

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.