Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Executive Summary
Threat actors linked to a China‑aligned espionage group exploited CVE‑2026‑51990, a critical flaw in Tencent’s Sogou Input Method for Windows, to install the GrayRabbit backdoor. The vulnerability allows remote code execution, enabling attackers to gain persistent access and exfiltrate data. The operation demonstrates the use of legitimate software to deliver malware and highlights the need for timely patching.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-13T14:26:32+00:00 - Category: threat-intel
Original Description: Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]
"I have been impressed with the urgency of doing. Knowing is not enough; we must apply. Being willing is not enough; we must do."
— Leonardo da Vinci