A cybersecurity company used AI to quickly develop a computer worm capable of hacking over a billion accounts on the Chinese messaging service WeChat.
Palo Alto-based Calif disclosed the already-patched computer worm to warn the public about the threat of AI-driven hacks. The attack, dubbed WeWorm, was developed after an AI model uncovered a serious remote code execution vulnerability in WeChat, a WhatsApp-like messaging service with over 1.4 billion users, mainly in China.
'Exploitation takes only seconds, and gives us full control of the WeChat account. We can read and send messages, make calls, and act on the victim's behalf,' the company warned, posting a video demo of the WeWorm attack.
As a computer worm, the threat can self-replicate, hacking one WeChat account and then moving to another by targeting users through their friend lists. The attack can also hit both Android and iOS WeChat accounts, spreading itself through phone calls on the app. 'The victim does not need to answer the call, or interact with their phone at all,' Calif added.
The good news is that WeChat's parent company, Tencent, patched the vulnerability after Calif notified the company in July. Specifically, the flaw involved a 'memory corruption issue in WeChat's VoIP stack,' or what the company described as an 'unconventional' attack surface.
The finding might cause some to call for a ban on AI amid signs that cybercriminals and state-sponsored hackers are using the technology, including open-source models, for their attacks. However, Calif notes that the WeChat vulnerability had existed for some time, meaning a human hacker could have uncovered it too. The problem is that AI models can discover and weaponize serious software bugs in days, whereas a human team would need months.
In this case, Calif used AI to discover the WeChat vulnerability in two days. 'Building the worm took one more week. A worm at this scale used to be the kind of thing that took a larger team months. AI can already do most of the work here,' the company added.
To prevent hackers from unleashing their own AI-developed computer worm, Calif is urging the industry and countries to use AI models to shore up their defenses and plug potential security holes. 'The US and China disagree on plenty, but keeping billions of people safe online shouldn't be one of them. AI gives us an opportunity to find and fix vulnerabilities faster than ever, and we should work together to make the world safer for everyone,' the company said.
Although Calif didn't disclose which AI program discovered the flaw, the company has been partnering with 'frontier labs,' suggesting it used a leading-edge model. It fears what might happen if bad actors gain access to similar models. 'All it takes is one lab accident or a person who grabs a half-finished version to unleash something like WeWorm into the world before anyone is ready,' Calif added.
(0)Comments