Researchers from the security company Calif developed an AI-powered tool capable of infiltrating mobile phones without the user needing to click on links or files. This system was created in less than a week.
The attack, named WeWorm, exploited a vulnerability that allowed it to hijack accounts and spread among contacts. Specialists interviewed by The New York Times warned that hundreds of millions of devices could be affected within a few hours.
The threat utilizes a method known as zero-click. Unlike phishing, which requires opening a link or file, this attack does not require user interaction. According to information from Calif, simply answering or letting an incoming call ring is enough to ensure penetration.
To prevent the attack, one must reject the call a few seconds after the first signal. Once control over the account is gained, the attacker can read and send messages, make calls, and manage the profile. Under certain conditions, access can lead to complete phone compromise.
The worm exploited an application privilege granting mechanism for numbers saved as friends. As soon as a contact became compromised, this trusted relationship helped the threat reach other numbers in the contact list.
Characteristics of rapid spread
The attack possessed several characteristics that contributed to its rapid dissemination. Vinh Nguyen, a former lead data specialist at the U.S. National Security Agency (NSA), classified this worm as one of the most alarming threats he had analyzed. He stated that 'hundreds of millions of devices' could be affected in just a few hours.
Calif reported that it combined open-source AI models with advanced systems developed in the United States. However, the company did not disclose which specific models were used.
This case draws attention to how quickly technology can aid in discovering and exploiting vulnerabilities. Nevertheless, AI did not perform all the work autonomously; researchers integrated the capabilities of the models with human expertise.
Additional Information
During a meeting with other AI leaders, Sam Altman, CEO of OpenAI, stated: 'Some things will go very badly with cybersecurity if some people do not act with great urgency.'
The vulnerability was patched after Calif contacted the company responsible for the affected application. The company stated that it saw no reason to believe the vulnerability jeopardized security or affected users, and also reported that an application update was not required.
Ty Duong, CEO of Calif, explained that tracking the process was necessary to turn the vulnerability into a worm. This incident demonstrates how the combination of AI and specialized knowledge can accelerate the transformation of a vulnerability into a widespread threat.
