A call comes in, the phone rings, you don't answer - and the attack could already be underway. Security researchers at Calif, a company based in Palo Alto, built a phone worm that works without a link, without a file and without the victim having to do anything at all. The attack was tested on WeChat, a messaging platform used mainly in China with more than 1.4 billion active users a month. But what is really alarming about it goes far beyond WeChat. According to the researchers, the worm worked on Apple's iOS as well as Google's Android and shows just how far attacks on smartphones can now go without the owner making any mistake at all. Calif calls the tool WeWorm. Once a WeChat account had been taken over, an attacker could read and send private messages, make calls and control the account. Combined with other security flaws, the company says it could even have been possible to take over the entire phone. The especially brutal part: Simply ignoring the call would not have been enough. Calif CEO Thai Duong said the attack worked both if the user answered and if the phone was simply allowed to keep ringing. Only someone who actively declined the call within a few seconds of the first ring would have prevented the takeover.
After that, the attack could have kept spreading on its own. WeChat gives saved contacts more permissions and trust than unknown numbers. That is exactly what WeWorm took advantage of. Once a number had been compromised, the worm could reach the victim's saved contacts, take over additional accounts there and then continue spreading from those accounts. Vinh Nguyen, formerly the chief data scientist at the U.S. National Security Agency and now at the Council on Foreign Relations, described the attack as one of the most alarming cases of its kind he had ever seen. In his assessment, hundreds of millions of devices could have been reached within a matter of hours. Computer worms that spread on their own have existed for decades. What is new is that an attack like this can hit mobile devices running the two major operating systems without anyone having to tap a malicious link or open a file. Calif says it took the team a little more than a week to build the tool. The researchers used freely available artificial intelligence models as well as powerful systems from the United States. The company has not said exactly which ones were used.
Tencent, the Chinese company behind WeChat, confirmed the vulnerability and closed it after Calif notified the company. According to Tencent, there is no indication that users were actually affected. Customers did not need to update the app. The White House was also briefed before the vulnerability was publicly disclosed. That means WeWorm remained a research attack and was not discovered as an active attack wave hitting millions of phones. That point should not get lost in the discussion. Still, the case shows how much faster security flaws can now be found and turned into working attacks. In the past, previously unknown flaws in operating systems or apps could be worth millions of dollars on illegal markets. Such vulnerabilities were rare, and exploiting them often required years of experience. Today, powerful systems can take a significant amount of that work off researchers' hands. Calif had already used an early version of Anthropic's Mythos model in May to bypass security protections in Apple's macOS. Anthropic itself said in April that Mythos had identified thousands of previously unknown security flaws in major operating systems and web browsers, including problems that had been sitting in software code for decades.
A machine still does not simply build attacks like this on its own. Duong explicitly says his team had to constantly supervise WeWorm and that human expertise was still necessary. But that is exactly where things are changing. A small number of specialists can now build things in far less time that once required significantly more people and more time. OpenAI and more than 100 major technology companies recently warned of an approaching wave of attacks in which artificial intelligence is likely to play an increasingly important role. Sam Altman said last week at a meeting of the G20 nations in North Carolina that some things in cybersecurity were going to go very wrong unless action was taken quickly. Bill Gates recently described dealing with these risks as one of the most urgent tasks in the world. For smartphone users, WeWorm is not currently an attack they need to be specifically afraid of. The WeChat vulnerability has been fixed, and there is no indication that any users were affected. But the idea that being careful alone is enough to stay safe has taken a serious hit. With this attack, nobody would have had to click on the wrong thing. The phone only had to ring.
Updates – Kaizen News Brief
Alle aktuellen ausgesuchten Tagesmeldungen findet ihr in den Kaizen Kurznachrichten.
To the Kaizen News Brief In English