Is WeWorm Actually a Worm?
# Is WeWorm Actually a Worm?
People are panicking on the wire this week. They found WeWorm, a zero-click exploit that spreads via WeChat calls on Android and iOS, and now everyone is calling it a return of the mobile epidemic. The logic makes sense. If an attacker hits a device without any user action and then automatically goes after that person's contact list, mobile sandboxing has failed. WeWorm isn't just another bug. It's a structural threat to mobile privacy.
I don't buy it.
Calling this thing a worm is technically correct if you're looking at how it spreads, but honestly, it's lazy thinking, and imagine spending millions of dollars to build a precision instrument that works on both XNU and Linux kernels. Would you use a diamond drill to smash a pile of bricks? Probably not. Developing stable zero-clicks for modern iOS and Android is incredibly expensive. No state actor or mercenary group would throw away an asset like that just to infect random people.
I'm moderately sure about this. To be totally certain, I'd need to see data showing thousands of low-value users getting hit all at once; right now, the evidence points toward precision rather than proliferation.
We have seen this movie before. Think back to 2017 with WannaCry. Everyone acted like it was some unstoppable monster. While it did spread via SMB, the chaos happened because companies didn't install a patch that had been sitting there for months; the similarity here is the panic. We often mistake bad digital hygiene or a targeted tool for a brand new species of threat. But where does the comparison stop? An open SMB port on a server is just sitting there like a target, but a WeChat call is a dynamic social interaction.
The numbers from this week show that we're looking in the wrong direction while real damage happens elsewhere. Why are we worrying about a theoretical mobile plague when 220 million traveler records were leaked from Vietnam APIS? CenterPoint Energy lost nearly 7.5 million records, and adobe fixed over 170 vulnerabilities and Microsoft patched 966 flaws, including two zero-days. These aren't theories. They are confirmed losses.
Then you have the Liquid Network theft of $320 million; just because "white hat" hackers gave back $266.5 million doesn't mean the hole wasn't dangerous. It just means the attackers were odd.
If the crowd is wrong about WeWorm being a mass threat, who wins? The attackers. By calling a targeted tool a worm, they make themselves look omnipotent. It's psychological warfare. If you think someone can take over your phone just by calling you, you'll probably buckle under pressure or stop talking to people.
The hype helps middle managers in the security industry too. They love selling "Mobile Threat Defense" suites, and these products barely stop zero-clicks since they work on a different layer than the vulnerability itself. But they sell great when you can point to a headline and tell a CISO that their current setup is blind.
The real danger isn't some phone pandemic, and it's what happens to people in restrictive regimes who need WeChat for encrypted talk. If everyone believes every call is compromised, those users might move to platforms that are even easier to monitor. That plays right into the hands of whoever is spying on them.
I think WeWorm will stay a boutique tool, and it is simply too pricey to burn on the general public. Maybe we're just bored with normal data breaches, even ones involving 220 million people, so we want a movie plot threat to keep us excited.
I'll change my mind if I see widespread, non-targeted crashes in WeChat across diverse demographics. Until then, the only thing actually spreading is the hype.
◼
Sources
The reporting this analysis was built from. Follow the originals before acting on anything here.
- N-able Patches Critical Zero-Day in N-central SecurityWeek
- Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day SecurityWeek
- Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell The Hacker News
- MikroTik Patches Critical Flaws Chained to Hack Routers SecurityWeek
- WeWorm - The first zero-click worm to spread through WeChat calls across iOS and Android. r/netsec
- Mathspace breach exposes data on over a million students and parents - Help Net Security Google News Security
- 220 million traveler records exposed in Vietnam-linked APIS leak BleepingComputer
- WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls The Hacker News