Calif Research 展示 WeChat 零点击蠕虫 WeWorm

内容摘要
Calif Research近日发布了一款名为WeWorm的零点击蠕虫,该蠕虫可通过iOS和Android平台的WeChat通话传播。受害者无需接听电话或与手机互动,即使接听电话,也不会听到任何声音,但攻击仍然成功。该团队利用AI技术,在两天内发现了漏洞并编写了首个远程代码执行(RCE)漏洞利用程序,构建蠕虫则花费了一周时间。在过去,这种规模的蠕虫需要更大团队数月时间完成,而现在AI技术已能完成大部分工作。团队提供了关于目标选择和如何安全测试的判断。
Calif Research近日发布了一款名为WeWorm的零点击蠕虫,该蠕虫可通过iOS和Android平台的WeChat通话传播。受害者无需接听电话或与手机互动,即使接听电话,也不会听到任何声音,但攻击仍然成功。该团队利用AI技术,在两天内发现了漏洞并编写了首个远程代码执行(RCE)漏洞利用程序,构建蠕虫则花费了一周时间。在过去,这种规模的蠕虫需要更大团队数月时间完成,而现在AI技术已能完成大部分工作。团队提供了关于目标选择和如何安全测试的判断。

Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. [...]

The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds. [...]

Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days. Building the worm took one more week.

A worm at this scale used to be the kind of thing that took a larger team months. AI can already do most of the work here. Our team provided the judgment about what to target and how to test it safely.

Calif Research, WeWorm

原始发布方:Simon Willison 博客

原文时间:2026-09-10 08:56:41 +08:00

阅读原文 · 数据来源:AIHOT

提示

本文用于信息整理与经验分享。第三方订阅、支付及账号服务可能调整,实际规则、价格和可用性请以下单页面及服务方最新说明为准。

咨询 GPT 充值咨询充值