Hackers exploit Tencent app flaw to deploy GrayRabbit malware
BLUF
Critical vulnerability in popular input software is being actively exploited for espionage.
NEWS
Threat actors associated with a China-aligned group are weaponizing CVE-2026-51990 in Tencent's Sogou Input Method for Windows. This exploitation allows attackers to deploy the GrayRabbit backdoor, granting persistent remote access to victim systems.
Why I Care
This matters because input methods are ubiquitous on Windows systems, making a large user base vulnerable to state-sponsored espionage and data theft. Successful exploitation leads to long-term compromise of sensitive corporate or personal information without immediate detection.
Next Steps
IT administrators should patch Tencent Sogou Input Method immediately or disable the application if updates are unavailable. End-users must verify their software versions and apply security patches released by Tencent as soon as possible to mitigate risk.
Source: BleepingComputer ·