ZeroHour

Search: “Friend”

882 stories

WeChat Worm Can Hijack Accounts Without Victims Answering Calls

Researchers demoed WeWorm, a zero-click WeChat worm hijacking accounts via incoming VoIP calls using a memory corruption flaw; Tencent patched it in August.

Researchers at Calif exploited a memory corruption bug in WeChat's VoIP system, taking over accounts through an incoming call even if the victim never answers or touches the phone. The attacker must already be a WeChat contact, but compromising a friend's account bypasses this, and chained calls spread the worm across three Android and iOS test phones in seconds. Tencent fixed the flaw in Android 8.0.77 and iOS 8.0.76 released in August, and researchers found no evidence of real-world exploitation. WeChat and Weixin reported 1.418 billion combined monthly active users at the end of 2025.

Security Affairs · 8d agoExploit / PoC

Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft

Malone Lam's plea hearing approaches in the $240 million bitcoin social engineering theft; the case highlights surging crypto fraud and limited enforcement.

Malone Lam, accused of organizing a social engineering attack that stole over $240 million in bitcoin (4,100+ BTC) from a Washington, D.C. resident in August 2024, has a plea agreement hearing set. Callers impersonating Google and Gemini staff tricked the victim into revealing security codes. Lam and 17 co-defendants spent lavishly before FBI arrests; crypto investment fraud complaints to the FBI rose nearly 50% in 2025 while DOJ disbanded its crypto crimes unit.

SecurityWeek · 8d agoPolicy & legal