WeWorm is a proof-of-concept zero-click worm targeting WeChat voice-call handling on Android and iOS. It reportedly exploits a memory-corruption vulnerability in WeChat's VoIP stack while an incoming call is ringing, without requiring the recipient to answer or otherwise interact. Successful exploitation provides control of the victim's WeChat account, permitting an operator to read and send messages, place calls, and impersonate the account holder within WeChat. The worm propagates by using a compromised account to call contacts in its saved friend network, enabling cross-platform spread between Android and iOS users. The underlying issue was reported to Tencent, which released application updates and deployed a server-side mitigation. WeWorm is associated with security research company Calif and was presented as a research demonstration rather than an identified in-the-wild malware campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cross-platform, zero-click WeChat worm that exploits a memory-corruption vulnerability in WeChat's VoIP stack through a call. It hijacks victims' WeChat accounts, propagates by calling saved contacts, and enables reading and sending messages, making calls, and impersonating the victim. When chained with separate Android or iOS vulnerabilities, it could provide full device control.
Ein plattformübergreifender Zero-Click-Wurm, der über WeChat-VoIP-Anrufe zwischen gespeicherten Kontakten unter Android und iOS Account-Übernahmen ermöglichen konnte, ohne dass ein Anruf angenommen werden musste. Eine vollständige Smartphone-Übernahme hätte zusätzliche Schwachstellen benötigt.
Proof-of-concept zero-click worm exploiting a memory-corruption flaw in WeChat's VoIP call-handling stack. It reportedly compromises a victim's WeChat account without requiring the call to be answered, then can read and send messages, place calls, impersonate the user, and propagate through the compromised account's friend list. The content states that chaining it with additional device-level vulnerabilities could enable full Android or iOS device control.
Proof-of-concept cross-platform, zero-click worm that exploits a memory-corruption flaw in WeChat's VoIP call-handling stack. It can compromise a victim's WeChat account during an unanswered incoming call, then use the compromised account and its trusted friend list to propagate to further contacts. The reported account access permits reading and sending messages, making calls, and acting as the victim; the content states that additional device-level vulnerabilities could potentially extend access to control of the underlying Android or iOS device.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.