Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Executive Summary

Threat actors linked to a China‑aligned espionage group exploited CVE‑2026‑51990, a critical flaw in Tencent’s Sogou Input Method for Windows, to install the GrayRabbit backdoor. The vulnerability allows remote code execution, enabling attackers to gain persistent access and exfiltrate data. The operation demonstrates the use of legitimate software to deliver malware and highlights the need for timely patching.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-13T14:26:32+00:00 - Category: threat-intel

Original Description: Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]

"I have been impressed with the urgency of doing. Knowing is not enough; we must apply. Being willing is not enough; we must do."

— Leonardo da Vinci
Source: Bleeping Computer