Cybersecurity company Calif revealed that it quickly developed the first WeChat/WeChat zero-click worm virus using AI, WeWorm, which can spread through cal...
行业动态IT之家(RSS)
Today AI Intelligence Brief
Cybersecurity company Calif revealed that it quickly developed the first WeChat/WeChat zero-click
worm virus using AI, WeWorm, which can spread through calls and take over applications within seconds. In July, the team used AI tools to discover a memory corruption issue in the VoIP protocol stack. With AI assistance, they wrote a remote code execution vulnerability in 2 days and spent another 7 days completing the worm; Tencent confirmed that the related vulnerability has been fixed on client Android 8.0.77, iOS 8.0.76, and server-side platforms, and users are currently unaffected.
Calif 在今年 7 月的某个时候利用 AI 工具发现了微信 / WeChat 中存在的 VoIP 协议栈内存损坏问题,此后该团队在 AI 的辅助下仅用时 2 天就编写了首个远程代码执行漏洞,完整制作蠕虫病毒则又花了 7 天时间。
Calif 指出,这么大规模的蠕虫病毒过去需要大型团队消耗数个月的时间才能完成,而现在 AI 已能完成大部分的工作。 人工智能具备加速引爆大量网络安全“暗雷”的能量 , 防御方也应积极使用人工智能来化解潜在风险 。
Intelligence Assessment
Aioga 编辑摘要
网络安全企业 Calif 披露 WeWorm,称其利用 AI 短时间内开发出首个面向微信或 WeChat 的零点击蠕虫。该蠕虫可通过通话传播并接管应用;腾讯确认相关漏洞已在客户端和服务器端修复,用户当前不受影响。
背景分析
Calif 称其在今年 7 月利用 AI 工具发现微信或 WeChat VoIP 协议栈中的内存损坏问题,并在 AI 辅助下用 2 天编写远程代码执行漏洞、再用 7 天完成蠕虫。WeWorm 可通过联系人继续扩散。
Aioga 观点
Aioga 判断:材料将事件重点放在 AI 对漏洞发现、远程代码执行编写和蠕虫制作流程的加速上;但公开材料主要提供 Calif 的披露与腾讯的修复确认,尚不足以独立验证全部技术细节。
影响与后续
可能影响:该披露可能提示 AI 工具正在改变部分网络安全研究与攻击代码开发流程,但漏洞已在客户端和服务器端修复,且来源称当前用户不受影响,因此不代表现有用户面临持续风险。防御方需要关注相关风险。 后续观察:继续核对腾讯及微信客户端公告,关注 Android、iOS 客户端与服务器端修复说明,以及 Calif 后续公开的漏洞细节和验证材料;在来源没有披露更多信息前,不对影响范围作扩大判断。
Source and Copyright
The readable text on this page was extracted from the public source and organized with attribution, publication time and the original link. Copyright remains with the original author and publisher.
Cybersecurity company Calif revealed that it quickly developed the first WeChat/WeChat zero-click worm virus using AI, WeWorm, which can spread through cal...
IT之家(RSS)2026-09-08T09:59:36.000Z
Scan to open this article
Aioga aggregates global AI updates and preserves source information for verification and citation.