Researchers Build WeChat Worm Using AI Assistance
Security researchers have demonstrated a zero-click worm targeting WeChat on iOS and Android, using artificial intelligence to drastically accelerate the development of the exploit.
Cybersecurity researchers have demonstrated a proof-of-concept zero-click worm, dubbed WeWorm, capable of spreading through WeChat voice calls on both iOS and Android devices. The exploit requires absolutely no user interaction, meaning victims do not even need to answer the incoming call for their devices to become compromised. Even if a target does pick up, they hear nothing while the underlying exploit successfully executes in the background, allowing the malware to propagate silently to other contacts.
The most notable aspect of the development is the speed at which it was completed, thanks to the integration of artificial intelligence. By collaborating with AI tools, the research team identified the underlying vulnerability and drafted a functional remote code execution exploit in approximately two days. From there, the team spent just one additional week building the fully functional worm. This rapid timeline represents a massive shift in how complex cyber weapons are constructed.
Historically, engineering a zero-click exploit of this sophistication and scale required a dedicated team of highly skilled security researchers working over several months. The creators of WeWorm noted that AI is now capable of handling the vast majority of the technical heavy lifting. The human researchers primarily provided the high-level judgment regarding what vulnerabilities to target and how to safely test the resulting code.
This rapid development cycle highlights a shifting landscape in cybersecurity, where offensive capabilities are being supercharged by generative AI. As automated tools lower the barrier to entry for creating complex exploits, security professionals warn that traditional patch management and threat detection strategies must evolve to counter AI-accelerated threats. The ease with which a small team can now produce sophisticated malware underscores the urgent need for robust, AI-driven defensive measures.
This is our own summary of reporting by Simon Willison



