Hackers Exploit Tencent Vulnerability to Spread GrayRabbit Malware
A critical flaw in the Sogou Input Method is being leveraged for espionage
14 hours ago
13 September, 20:151 min read
As reported by BleepingComputer, cybersecurity researchers have identified a new campaign linked to a China-aligned espionage hacking group. The attackers are exploiting a critical security vulnerability within the popular Sogou Input Method for Windows, developed by Tencent, to plant a backdoor known as GrayRabbit on victims' systems.
The vulnerability has been assigned the identifier CVE-2026-51990. According to experts, hackers are leveraging this flaw to gain unauthorized access to devices and covertly distribute the GrayRabbit malicious code.
Security Risks and Scope of Attack
Sogou Input Method is a widely used tool on the Windows operating system. Consequently, this critical vulnerability poses a significant risk to both individual users and organizations that rely on the software.
Researchers believe the group behind this campaign is engaged in state-sponsored cyber espionage. The GrayRabbit malware allows attackers to maintain persistent, hidden access to infected devices.
Defensive Measures
Experts strongly advise all users of the software to check for updates immediately and ensure that all relevant security patches are installed. Such incidents serve as a reminder that keeping software up to date is a fundamental requirement for maintaining robust cybersecurity.