Security researchers have demonstrated a new attack vector for the widely used WeChat platform, showing how a worm can propagate and seize control of user accounts without any interaction beyond a single incoming call. The exploit requires the victim to do nothing, highlighting a critical vulnerability in the application's handling of call notifications.

According to disclosures first reported by Security Affairs, a team at the firm Calif crafted a malicious worm that exploits a flaw in WeChat's call mechanism. The attack sequence begins when a call is placed from an account that is already in the victim's contact list. Merely receiving the call is enough to trigger the worm, which then takes over the device and spreads itself further — all without the call ever being answered or the phone touched.

The core danger lies in the complete absence of required victim action. The worm operates silently in the background upon receiving the incoming call, making it a potent tool for large-scale, automated account takeover campaigns. Once active, it automatically propagates through the compromised user's entire contact list, creating a chain reaction ideal for mass infections.

Tencent has since blocked the exploit and issued a patch following responsible disclosure. The company's swift action underscores the severity of the vulnerability, which granted attackers the ability to turn a core communication feature into a tool for widespread compromise.

This incident highlights a persistent systemic challenge for software developers: everyday, passive features can be weaponized as attack vectors. For the millions of WeChat users globally, it reinforces the necessity of applying updates promptly. As threat actors increasingly seek methods that circumvent user awareness, this exploit stands as a clear example of the sophisticated risks in the modern application landscape.


安全研究人員展示了針對廣泛使用的微信平台的一種新攻擊向量,顯示蠕蟲如何在僅僅接獲一個來電之外無需任何互動的情況下傳播並奪取用戶賬戶的控制權。此利用程序要求受害者什麼都不做,凸顯了該應用程式在處理來電通知時的一個關鍵漏洞。

根據 Security Affairs 最先報導的披露資訊,公司 Calif 的一個團隊製作了一個惡意蠕蟲,利用了微信通話機制中的一個缺陷。攻擊序列始於一個已存在於受害者聯絡人列表中的賬戶發起通話。僅僅接獲該通話便足以觸發蠕蟲,隨後蠕蟲會接管設備並進一步傳播自身——全程無需接聽通話或觸碰手機。

核心危險在於完全無需受害者採取任何行動。蠕蟲在接收到來電後便在後台靜默運行,使其成為大規模、自動化賬戶接管行動的強大工具。一旦啟動,它便自動通過被入侵用戶的整個聯絡人列表傳播,創造出適合大規模感染的連鎖反應。

騰訊隨後封鎖了該利用程序,並在負責任的披露後發布了補丁。該公司的迅速行動凸顯了該漏洞的嚴重性,該漏洞賦予了攻擊者將核心通訊功能轉化為大規模入侵工具的能力。

此次事件凸顯了軟件開發商持續面臨的系統性挑戰:日常、被動的功能可能被武器化成為攻擊向量。對於全球數以百萬計的微信用戶而言,它強調了及時應用更新的必要性。隨著威脅行為者日益尋求繞過用戶察覺的方法,此利用程序成為現代應用程式環境中複雜風險的一個明確例證。

新聞來源 / Original News Source