$ techbeacon▋
CVE & Exploits

Chinese‑aligned hackers weaponize Tencent input‑method flaw to spread GrayRabbit backdoor

Chinese‑aligned hackers weaponize Tencent input‑method flaw to spread GrayRabbit backdoor

A critical vulnerability identified as CVE-2026-51990 in Tencent's Sogou Input Method for Windows is being actively abused by threat actors tied to a China‑aligned espionage group. The flaw enables the silent installation of the GrayRabbit malware, a sophisticated backdoor that has appeared in several recent intelligence‑gathering campaigns.

Sogou Input Method, a widely used Chinese‑language keyboard and predictive‑text tool, is pre‑installed on many Windows PCs in China and among diaspora communities. Security researchers say the vulnerability resides in the program's handling of specially crafted input data, allowing attackers to execute arbitrary code with the privileges of the logged‑in user.

Once the exploit chain is triggered, the GrayRabbit payload is dropped onto the compromised system. The backdoor is designed to establish encrypted communications with command‑and‑control servers, enabling remote operators to exfiltrate files, capture keystrokes, and execute additional malicious modules. Its modular architecture makes it adaptable for a range of espionage objectives.

The campaign was first highlighted by BleepingComputer, which cited technical analyses that link the activity to a known China‑aligned espionage group. While the precise identity of the group remains unconfirmed, its tactics—targeting popular domestic software to reach a broad user base—mirror previous operations attributed to state‑sponsored actors seeking intelligence from both government and commercial targets.

Security experts recommend that users of Sogou Input Method immediately apply the patch released by Tencent, disable the software if it is not essential, and run reputable anti‑malware scans to detect any remnants of GrayRabbit. Organizations are urged to monitor network traffic for unusual outbound connections that could indicate backdoor activity. The incident underscores the broader risk posed by supply‑chain vulnerabilities in ubiquitous software, prompting calls for stricter code‑review processes and faster patch distribution in the industry.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related