By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Hackers Exploit Tencent App Flaw for GrayRabbit Malware
China-aligned threat actors are actively exploiting a critical vulnerability, identified as CVE-2026-51990, within Tencent's Sogou Input Method for Windows. This exploit allows the adversaries to deploy the GrayRabbit backdoor, a piece of malware associated with espionage activities. The vulnerability was discovered and detailed by security researchers at Palo Alto Networks' Unit 42. The exploitation of CVE-2026-51990 enables attackers to gain a foothold on compromised systems, facilitating further malicious operations. The GrayRabbit backdoor is designed to provide persistent access and enable various post-exploitation activities, including data exfiltration and lateral movement within a target network. This particular threat group is known for its focus on espionage, suggesting that the targets of this attack are likely organizations or individuals of strategic interest to the Chinese state. The Sogou Input Method is a widely used input method editor (IME) in China, developed by Sogou, a subsidiary of Tencent. Its widespread adoption means that a vulnerability within it could potentially affect a large number of users and organizations. The nature of the vulnerability, CVE-2026-51990, allows for remote code execution, meaning attackers can trigger malicious code on a victim's machine without requiring any user interaction beyond the initial exploitation vector. This makes it a particularly dangerous flaw. Palo Alto Networks' Unit 42 has provided technical details on the exploitation, including indicators of compromise (IoCs) to help organizations detect and respond to potential attacks. The researchers also noted that the attackers are leveraging the compromised input method to establish a command-and-control (C2) channel, which is essential for managing the infected systems and directing further malicious actions. The GrayRabbit backdoor itself has been observed in previous campaigns targeting various sectors, including government, technology, and telecommunications. Its inclusion in this attack chain underscores the persistent and evolving nature of state-sponsored cyber threats. The exploitation of widely used software like an input method editor highlights a common tactic among advanced persistent threat (APT) groups, as it provides a broad attack surface and a seemingly innocuous entry point. Organizations using Sogou Input Method for Windows are advised to apply any available security patches or updates from Tencent and to monitor their networks for any signs of compromise. The discovery and reporting of this vulnerability by Unit 42 are crucial steps in mitigating the impact of such attacks and enhancing overall cybersecurity posture against sophisticated threat actors. The ongoing efforts by cybersecurity firms to identify and publicize these vulnerabilities are vital in the global fight against cyber espionage and malware deployment.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.