CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7158

As cited

Copy frozen at (site build).

vulnerabilities

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Threat actors associated with a China-aligned espionage group are actively exploiting CVE-2026-51990, a critical vulnerability in Tencent's Sogou Input Method for Windows, to install the GrayRabbit backdoor. The flaw provides a direct path to compromise systems running the widely deployed input tool.

Why it matters: Organizations with Sogou Input Method deployed in Windows environments face immediate risk of backdoor installation and potential data exfiltration by state-sponsored actors; patching CVE-2026-51990 is urgent.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary