← 深度专栏/原创观点
原创观点

The AI Threat Multiplier: Building a Zero-Click Worm in Days

The most dangerous cyberattacks are the ones you never see coming. In the cybersecurity world, “zero-click” exploits—where a device is compromised without the...

潜
作者
潜龙编辑部
关注 AI 与社会议题
发布于
2026/10/5
READ
长读
The AI Threat Multiplier: Building a Zero-Click Worm in Days
illustration · QianLong editorial

The most dangerous cyberattacks are the ones you never see coming. In the cybersecurity world, “zero-click” exploits—where a device is compromised without the user ever tapping a link, opening an attachment, or answering a prompt—are considered the holy grail for hackers. They bypass human psychology entirely, relying purely on software vulnerabilities.

Recently, a security group known as Calif Research demonstrated exactly how accessible these elite threats are becoming. They unveiled “WeWorm,” a proof-of-concept zero-click worm designed to spread through WeChat audio calls across both iOS and Android devices. The mechanics are chillingly simple from the victim's perspective: if a targeted phone rings, the exploit succeeds. The user does not need to answer the call, and even if they do, they hear nothing while the device is silently compromised.

However, the truly alarming part of this demonstration isn't the vulnerability itself, but the unprecedented speed at which it was weaponized. Historically, engineering a cross-platform, zero-click worm of this magnitude required a large team of highly skilled developers working meticulously for months.

This time, by leaning heavily on artificial intelligence, the Calif Research team found the underlying bug and wrote the initial remote code execution (RCE) exploit in just two days. Within a single additional week, the fully functional worm was complete.

AI acted as a massive force multiplier in this scenario. According to the researchers, the artificial intelligence handled the vast majority of the technical heavy lifting. The human engineers simply provided the strategic judgment—deciding what specific systems to target and ensuring the testing environment remained safely contained.

This dramatic compression of the development timeline signals a fundamental shift in the cybersecurity landscape. AI is rapidly lowering the barrier to entry for creating sophisticated malware. When the bottleneck for cyberattacks shifts from technical execution to mere intent, the threat landscape expands exponentially. Malicious actors, who previously lacked the resources or technical chops to build complex worms, may soon be able to direct AI agents to do the work for them.

Fortunately, this specific research was conducted by security professionals aiming to expose these dynamics before they can be widely abused in the wild. Yet, the broader implications are clear: we are entering a high-stakes arms race where AI-powered defense systems will have to constantly battle AI-generated threats. For everyday users, while there is no need for outright panic, fundamental digital hygiene—specifically, keeping operating systems and applications relentlessly updated—is no longer just good advice; it is a critical necessity.

Key Points

  • Security researchers used AI to build a 'zero-click' worm targeting WeChat in just over a week.
  • The exploit works across iOS and Android without requiring the victim to answer the call or touch their phone.
  • AI handled the heavy technical lifting, drastically reducing a process that used to take large teams several months.
  • The experiment highlights how AI acts as a force multiplier, lowering the barrier to entry for complex cyberattacks.

Why It Matters

By collapsing the time and resources needed to develop elite cyber threats, AI is fundamentally changing the cybersecurity landscape, making rapid software updates more critical than ever for everyday users.


Sources:

潛
本文完
潜龙编辑部 · 2026/10/5
潜龙 QianLong · 中文 AI 内容与工具平台