Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Refract AI Intelligence Digest

BLUF

Critical vulnerability in popular input software is being actively exploited for espionage.

NEWS

Threat actors associated with a China-aligned group are weaponizing CVE-2026-51990 in Tencent's Sogou Input Method for Windows. This exploitation allows attackers to deploy the GrayRabbit backdoor, granting persistent remote access to victim systems.

Why I Care

This matters because input methods are ubiquitous on Windows systems, making a large user base vulnerable to state-sponsored espionage and data theft. Successful exploitation leads to long-term compromise of sensitive corporate or personal information without immediate detection.

Next Steps

IT administrators should patch Tencent Sogou Input Method immediately or disable the application if updates are unavailable. End-users must verify their software versions and apply security patches released by Tencent as soon as possible to mitigate risk.

Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.