CYBERSECURITY

WeChat Zero-Click Worm Exploits Incoming Calls on Mobile Devices

WeChat Zero-Click Worm Exploits Incoming Calls on Mobile Devices

How the Zero-Click Mechanism Bypasses User Awareness

Security researchers at the firm Calif have developed a sophisticated worm capable of hijacking WeChat accounts on both i Phone and Android devices. The attack vector relies entirely on incoming calls, requiring no user interaction whatsoever. The team successfully demonstrated the malware spreading across three separate test phones. This discovery highlights a critical vulnerability in how mobile operating systems handle background processes during communication events.

The exploit functions through a zero-click mechanism, meaning the victim does not need to answer the phone or even notice the call. The only prerequisite is that the attacker must already exist in the victim’s contact list. Once the incoming call triggers the vulnerability, the worm executes code in the background. It then establishes a persistent foothold within the WeChat application. From there, it can exfiltrate data or spread to other contacts automatically.

Why Existing Contacts Are Critical to the Attack Chain

Traditional mobile malware often requires users to click a link or install an app. This new approach eliminates that friction entirely. The researchers noted that standard security patches may not fully address this specific race condition. When a call arrives, the system allocates resources for the audio stream. The worm intercepts this process before the user interface updates. Consequently, the malicious code runs silently. Victims remain unaware until they notice unusual activity in their chat history. The attack chain is complex but highly reliable once the initial conditions are met.

The requirement for the attacker to be a saved contact significantly limits the scope of immediate exploitation. Random strangers cannot initiate the worm unless they first add themselves to the victim’s address book. This constraint suggests the threat is most dangerous in targeted attacks. Sophisticated actors could use social engineering to get added to high-value targets. Once inside, the worm can leverage the compromised account to reach new victims. It creates a cascading effect where each infected phone becomes a node in the network. The researchers emphasized that this dynamic makes containment difficult without manual intervention.

Does the victim need to answer the call? No, the victim does not need to pick up the phone. The exploit triggers automatically when the incoming call event occurs. The phone does not even need to be unlocked for the code to execute.

Frequently Asked Questions

Which platforms are affected by this worm? Both iOS and Android devices running the WeChat application are vulnerable. The researchers tested the exploit on multiple versions of both operating systems. No specific hardware model was immune to the attack.

How did the researchers demonstrate the spread? They used three test phones to simulate a small network. The worm moved from the first device to the second, and then to the third. This proved the capability for automated propagation without human assistance.

Content written by Marcus Reeves for tech-site.news editorial team, AI-assisted.

Comments

Leave a comment