零点击微信蠕虫:人工智能将令黑客攻击更危险?

Wait 5 sec.

DUSTIN VOLZ2026年9月9日安全公司Calif的研究人员最近仅用一周多时间就构建了一个黑客工具,能够在微信上横行肆虐。 Dado Ruvic/ReutersA friend you haven’t heard from in a while suddenly calls. You don’t pick up, but in a matter of seconds, the damage is already done.一个许久未联系的朋友突然打来电话。你没有接,但就在几秒钟内,损害已经造成。The call wasn’t actually from an old companion looking to reconnect, but from a hacker who had hijacked that number. Worse, the assailant now secretly has control over your account, including access to your private messages, and is already using your number to reach your saved contacts and compromise them, too.这通电话并非来自想要叙旧的老友,而是来自一个劫持了那个号码的黑客。更糟糕的是,入侵者现在已秘密控制了你的账户,包括访问你的私人消息,并且已经在用你的号码联系通讯录上的联系人,入侵他们的账户。Like a raging, highly contagious virus, the attack keeps spreading. Within hours, millions of people have suffered the same fate.就像一种来势汹汹、传染性极强的病毒,攻击不断蔓延。数小时内,数百万人遭受了同样的命运。A year ago, such a cyberattack might have sounded far-fetched to even the most paranoid digital experts, or at least like something only the world’s most elite spy agencies could have pulled off.一年前,即便是对最多疑的数字安全专家来说,这样的网络攻击也可能听起来遥不可及,或者至少像是只有世界上最顶尖的情报机构才能完成的操作。Instead, because of advanced artificial intelligence models, a small team of researchers at Calif, a security company based in Palo Alto, Calif., recently built a hacking tool in a little more than a week that could run roughshod across WeChat, the social media and messaging platform ubiquitous in China.然而,由于先进的人工智能模型,位于加利福尼亚州帕洛阿尔托的安全公司Calif的一个小型研究团队最近仅用一周多时间就构建了一个黑客工具,它能够在微信——中国无处不在的社交媒体和即时通讯平台——上横行肆虐。“This bug is exceptional,” said Thai Duong, the chief executive of Calif, which says it builds hacking tools not to sell them but to bolster cyberdefense. The bug’s simplicity and powerful abilities, he added, would be “a dream come true” for hackers.“这个漏洞非同寻常,”Calif的首席执行官杨蔡(音)说,该公司表示开发黑客工具并非为了出售,而是为了加强网络防御。他补充说,这一漏洞的简单性和强大的功能对黑客来说将是“梦想成真”。The attack is the latest — and one of the most alarming — demonstrations yet of the breakneck speed at which A.I. is progressing, outpacing the ability of regulators and even of leading developers to keep up.这次攻击是人工智能以惊人速度发展的最新、也是最令人担忧的例证之一,其发展速度已超出了监管机构乃至顶尖开发者跟上这一发展步伐的能力。Calif said the attack, which it named WeWorm, was the first known computer worm — a type of malicious software that can leap from machine to machine on its own absent human help — that could spread across Apple’s iOS and Google’s Android operating systems without needing a victim to click or tap on anything. So-called zero-click attacks are different, and far more lethal, than standard phishing emails and texts. They are considered especially pernicious because they are so hard to defend against, given that they do not require a victim to step into a digital booby trap.Calif表示,这次被其命名为“WeWorm”的攻击是已知的第一个无需受害者点击或触碰任何东西就能在苹果iOS和谷歌Android操作系统之间传播的计算机蠕虫,蠕虫是一种无需用户干预即可自行从一台机器跳至另一台机器的恶意软件。所谓的零点击攻击与标准的网络钓鱼电子邮件和短信不同,其危害性要大得多。这类攻击尤其令人防不胜防,因为它们根本不需要受害者主动踩进某个数字世界里的“陷阱”。A spokeswoman for Tencent, the Chinese technology company that owns WeChat, confirmed the vulnerability and said that it had fixed the issue after being contacted by Calif.拥有微信的中国科技公司腾讯的一位发言人证实了该漏洞的存在,并表示在接到Calif的联系后已修复了该问题。The company had no reason to believe the issue compromised security or affected any users, the spokeswoman said in a statement, adding that no app updates were required by customers.该发言人在声明中表示,公司没有理由相信该问题危及了安全或影响了任何用户,并补充说用户无需更新应用程序。The discovery is still likely to fuel more concerns that advanced A.I. models could soon usher in a dystopian future that shatters core assumptions about digital security and, at least in the short term, delivers a major advantage to malicious hackers. Calif said it relied on a combination of open-source A.I. models and leading models from the United States, but it declined to specify which ones.这一发现仍可能引发更多担忧,即先进的人工智能模型可能很快带来一个反乌托邦的未来,粉碎关于数字安全的核心假设,并且至少在短期内为恶意黑客提供巨大优势。Calif表示,它依赖于开源人工智能模型和美国领先模型的组合,但拒绝透露具体是哪些模型。In recent weeks, OpenAI and more than 100 major technology companies, including Calif, warned in an open letter that a wave of A.I.-enabled cyberattacks was coming, and that organizations and governments needed to prepare. The letter followed a spate of cyberattacks from A.I. models, with the models in some cases breaking out of testing environments and attacking other companies. Bill Gates, the billionaire co-founder of Microsoft, said in an interview with The New York Times that addressing these risks should be “the world’s top priority.”近几周,OpenAI以及包括Calif在内的100多家主要科技公司在一封公开信中警告,一波人工智能驱动的网络攻击即将来临,企业和政府都需要做好准备。这封公开信发布之前,已出现了一系列来自人工智能模型的网络攻击,在某些情况下,这些模型甚至突破了原本用于测试的环境,并对其他公司发起攻击。微软联合创始人、亿万富翁比尔·盖茨在接受《纽约时报》采访时表示,应对这些风险应该成为“全球的头等大事”。OpenAI首席执行官萨姆·奥特曼上周表示:“除非有人立即采取行动,否则网络安全方面将会出现非常严重的问题。” Sean Rayford/Getty Images“We have a big challenge in front of us,” Sam Altman, the chief executive of OpenAI, said last week at a Group of 20 nations meeting in North Carolina. “Some things are going to go very wrong with cybersecurity unless some people act quite urgently.”“我们面临着一个巨大挑战,”OpenAI首席执行官萨姆·奥特曼上周在北卡罗来纳州举行的二十国集团会议上表示。“除非有人立即采取行动,否则网络安全方面将会出现非常严重的问题。”In the WeWorm attack, once a WeChat account was compromised, a hacker could have read and sent messages, made calls and controlled the victim’s account. Computer worms leverage software vulnerabilities that do not require clicking on a link or a file to automatically deploy their code across a network or the internet, allowing them to spread quickly and easily — in this case, across WeChat accounts. Combined with other security bugs, an attacker could have used the access to a WeChat account to fully compromise a victim’s phone, Calif said.在WeWorm攻击中,一旦微信账户被攻破,黑客就可以读取和发送消息、拨打电话并控制受害者的账户。计算机蠕虫利用软件漏洞,无需点击链接或文件就能自动在网络或互联网上部署其代码,使其能够快速轻松地传播——在这次事件中,是在微信账户之间传播。Calif表示,结合其他安全漏洞,攻击者可以利用对微信账户的访问权限完全控制受害者的手机。WeChat has over 1.4 billion active users each month, the company said in a blog post this year, making it one of the world’s most widely used apps. Nearly all of its users are based in China. President Trump is scheduled to host the Chinese leader Xi Jinping this month, and the two men are expected to discuss A.I.腾讯在今年的一篇博客文章中表示,微信每月有超过14亿活跃用户,使其成为世界上使用最广泛的应用程序之一。它的几乎所有用户都在中国。特朗普总统定于本月接待中国领导人习近平,两人预计将讨论人工智能问题。Calif briefed White House officials before publicly disclosing the vulnerability. When asked about the attack, a White House official acknowledged the briefing, noting that A.I. was paving the way for quicker, more advanced attacks and drastically empowering cyber defenders.Calif在公开披露该漏洞之前向白宫官员通报了情况。当被问及此次攻击时,一位白宫官员承认了通报,并指出人工智能正在为更快、更先进的攻击铺平道路,同时也极大地增强了网络防御者的能力。In a short research summary published on Tuesday that was reviewed by The Times, Calif said the attack took advantage of how WeChat trusts numbers saved as friends by an account, allowing compromises to spread rapidly from phone to phone. It works if a targeted WeChat user picks up the call or lets it ring, said Mr. Duong, Calif’s chief executive. Only declining the call seconds after a phone’s first buzz would prevent infiltration.在周二发布的一份简短的研究摘要中,Calif公司表示,这次攻击利用了微信对账号中已保存为好友的电话号码的信任机制,从而使入侵能够迅速从一部手机蔓延到另一部手机。《纽约时报》获得了这份报告。Calif首席执行官杨蔡表示,如果被攻击的微信用户接听了电话或任其响铃,攻击就会成功。只有在手机第一次震动后几秒钟内拒接电话,才能阻止攻击者入侵。“WeChat, like many messaging apps, gives trusted contacts more privileges,” the summary said. “But once one contact is compromised, that trust works against you.”“微信和许多即时通讯应用一样,给予受信任的联系人更多权限,”摘要写道。“但一旦一个联系人被入侵,这种信任就会反噬你。”Vinh Nguyen, a former chief data scientist at the National Security Agency who reviewed Calif’s research before its publication, said the WeChat worm was one of the most troubling and potentially severe cyberattacks he had ever seen. While self-propagating computer worms have been unleashed before, they were more common decades ago and did not involve mobile software.曾在国家安全局担任首席数据科学家的阮明(音)提前审阅了Calif的研究摘要,他表示,微信蠕虫是他所见过的最令人不安、潜在危害最严重的网络攻击之一。虽然自我传播的计算机蠕虫以前也曾被释放过,但它们更常见于几十年前,且不涉及移动软件。The WeChat worm was especially concerning because of its ability to rapidly compromise accounts and then automatically spread to all numbers saved in an account’s address book, allowing it to “propagate exponentially,” said Mr. Nguyen, who is now a senior fellow on A.I. at the Council on Foreign Relations. “Within hours, you could reach hundreds of millions of devices.”现为外交关系委员会人工智能高级研究员的阮明表示,微信蠕虫尤其令人担忧,因为它能够快速入侵账户,然后自动传播到账户通讯录中保存的所有号码,使其能够“呈指数级传播”。“在几小时内,你就可以感染数亿台设备。”Mr. Duong and his colleague Bruce Dang visited the Palo Alto offices of Tencent, hoping to speak to representatives about a problem they believed was dire. They were unable to find anyone there, however, and departed after taking a photo in front of a Tencent sign.杨蔡和他的同事布鲁斯·邓(音)前往腾讯位于帕洛阿尔托的办公室,希望能与代表讨论他们认为极其严重的问题。然而,他们扑了空,在腾讯标志前拍了一张照片后便离开了。Flaws like the one Calif identified are known as zero-day vulnerabilities — security holes that are unknown to software makers. They were once considered so rare and powerful that they could fetch millions of dollars on black markets used to sell hacking tools.像Calif发现的这种漏洞被称为零日漏洞——软件制造商未知的安全漏洞。它们曾一度被认为非常罕见且威力巨大,在用于销售黑客工具的黑市上可以卖到数百万美元。But new A.I. models appear to be able to find and weaponize zero-day bugs and other coding flaws that dwarf what security researchers and spy agencies, including the N.S.A., had believed were possible.但新的人工智能模型似乎能够发现和利用零日漏洞以及其他编码缺陷,其能力之强,令安全研究人员和包括国家安全局在内的情报机构都始料未及。When Anthropic’s new Mythos model was announced in April, the company said it had identified thousands of zero-day vulnerabilities “in every major operating system and every major web browser,” including many that were decades old. The dynamic has led Anthropic and other A.I. labs like OpenAI to initially limit the release of their newest, most powerful models to certain companies and government agencies. Doing so, they have argued, can allow major companies to patch critical software weaknesses.当Anthropic的新款Mythos模型在4月发布时,该公司表示,它已在“每个主要操作系统和每个主要网络浏览器中”识别出数千个零日漏洞,包括许多已存在数十年的漏洞。这种情况促使Anthropic和OpenAI等其他人工智能实验室最初将其最新、最强大的模型仅发布给特定公司和政府机构。它们认为,这样可以让大型企业有机会及时修补软件中的关键漏洞。The WeChat attack is just the latest finding from Calif to raise eyebrows. In May, the company disclosed to The Wall Street Journal that it had used an early version of the Mythos model to bypass security protocols in Apple’s macOS operating system, long viewed as highly secure and difficult to breach. Since Mythos and other powerful cyber-focused models built by competing A.I. labs were released to select organizations beginning in the spring, technology vendors have been reporting vastly more high-severity bugs than normal.针对微信的攻击只是Calif公司近期披露的又一个令人警觉的发现。今年5月,该公司向《华尔街日报》透露,他们曾利用早期版本的Mythos模型,绕过了苹果macOS操作系统的安全防护机制。长期以来,macOS一直被认为安全性很高、很难被攻破。自今年春季开始,Mythos以及竞争对手开发的、专门用于网络攻防的强大模型陆续向部分机构开放以来,科技厂商发现的高危漏洞数量远远高于正常水平。In the Apple and WeChat cases, the A.I. systems did not build attacks on their own but relied on mixing their talents with human cybersecurity expertise to discover and leverage them.在苹果和微信的案例中,人工智能系统并非自行构建攻击,而是依靠将其能力与人类网络安全专业知识相结合来发现和利用这些漏洞。“These skills came from years of manual work,” Mr. Duong said, adding, “To exploit it and build a worm, we also need to babysit the entire process.”“这些技能来自多年的人工工作,”杨蔡说,并补充道,“要利用它并构建蠕虫,我们还需要全程人工介入。”Dustin Volz为时报报道网络安全和情报领域新闻,常驻华盛顿。翻译:纽约时报中文网点击查看本文英文版。