A newly developed hacking tool powered by artificial intelligence has raised significant alarms within the cybersecurity community due to its potential for rapid and widespread digital attacks. Researchers at Calif, a Palo Alto-based security firm, recently created a worm capable of autonomously spreading through WeChat, a widely used social media and messaging platform in China with over 1.4 billion monthly users.
The vulnerability, dubbed “Webworm” by Calif, represents a novel zero-click attack — a method that compromises devices without requiring a user to click a link or download a file. This approach allows the malicious software to propagate swiftly, relying on WeChat’s trust mechanism that grants contacts saved in an account certain privileges. Once an account is infected, the worm can read and send messages, make calls, and use the victim’s account to target their saved contacts, enabling exponential spread to millions of users within hours.
Calif’s chief executive, Thai Duong, described the flaw as “exceptional” in its simplicity and effectiveness, making it a highly desirable tool for malicious hackers. The company emphasized that the tool was developed for cybersecurity research purposes, aimed at strengthening defenses rather than weaponizing the technology.
Tencent, the parent company of WeChat, acknowledged the vulnerability and confirmed that it had been addressed following Calif’s notification. A Tencent spokesperson stated there was no evidence that the flaw had led to a security breach affecting users, and no app updates were necessary for customers. However, the incident underscores the growing concerns surrounding the rapid advancements in artificial intelligence and their implications for cybersecurity.
The development of Webworm highlights the accelerating pace at which AI capabilities are outstripping traditional regulatory and defense measures. Experts note that AI-driven cyberattacks may soon become more frequent and sophisticated, raising challenges for governments and companies worldwide. This issue has gained attention from prominent technology leaders including Sam Altman, CEO of OpenAI, who warned of looming cybersecurity threats at a recent Group of Twenty meeting, and Bill Gates, who called for urgent action to mitigate AI-powered risks.
Calif’s findings were shared with White House officials prior to public disclosure, underscoring the U.S. government’s growing recognition of AI’s role in cybersecurity. Former National Security Agency chief data scientist Vinh Nguyen, now a senior fellow on AI at the Council on Foreign Relations, described the WeChat worm as one of the most troubling cyber threats he had seen, given its potential to compromise devices on a massive scale through automatic replication.
The emergence of tools like Webworm is part of a broader trend wherein AI models increasingly assist in identifying zero-day vulnerabilities — previously rare and valuable software flaws unknown to developers. Firms such as Anthropic recently revealed that their own AI models have detected thousands of such weaknesses across major operating systems and web browsers, further elevating concerns about the pace and scale of vulnerabilities being uncovered.
While AI systems aid in discovering and exploiting these flaws, researchers emphasize that human expertise remains essential to develop and control such attacks. Calif’s team combined AI tools with manual intervention to craft the worm and manage its spread.
The Webworm incident comes amid heightened geopolitical tensions and increasing scrutiny of AI’s role in cybersecurity, especially with upcoming discussions between U.S. President Donald Trump and Chinese President Xi Jinping. As AI continues to evolve rapidly, the balance between leveraging its benefits and mitigating its risks remains a critical challenge for the global technology community.
