WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

September 8, 2026 1 Min Read 0
Threat Intelligence Brief

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

Source: thehackernews.com
Threat Risk: Critical
Victim: Enterprise Organizations & Affected Platforms
Incident: WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
Impact: Unauthenticated remote exploitation, data theft, or compromise of exposed infrastructure.
Attacker: Active Threat Actors / Exploitation Groups
Analysis: Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones.

The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since…
Recommendations: Apply emergency vendor updates, monitor network perimeters, and isolate vulnerable endpoints.; Review authentication logs for anomalous remote commands.
Source: The Hacker News

Editorial note: this post summarizes high-priority intelligence and links to primary telemetry.
View Primary Telemetry →

Leave a Reply

Your email address will not be published. Required fields are marked *