Hackers associated with a China-aligned espionage group have been found exploiting a critical vulnerability in Tencent's Sogou Input Method for Windows. The flaw, identified as CVE-2026-51990, is being used to deploy the GrayRabbit backdoor, a sophisticated piece of malware.
The vulnerability in the Sogou Input Method, a popular Chinese input software, poses significant security risks. By leveraging this flaw, attackers can gain unauthorized access to affected systems, enabling them to install the GrayRabbit malware. This malware is designed to provide remote access and control over compromised devices, facilitating espionage activities.
The exploitation of this vulnerability highlights the ongoing threat posed by state-aligned cyber groups. These groups often target software vulnerabilities to infiltrate systems and gather sensitive information. The deployment of GrayRabbit is a testament to the persistent efforts of such actors to exploit software used widely across China and potentially beyond.
Tencent, a major Chinese technology company, is yet to release a statement regarding this specific vulnerability. Users of the Sogou Input Method are advised to stay vigilant and apply any available security updates to protect their systems from potential attacks.
This incident underscores the importance of regular software updates and security patches to safeguard against emerging threats. As cyber espionage continues to evolve, maintaining robust cybersecurity measures remains crucial for individuals and organizations alike.
<small>Source: Bleeping Computer — read the original story there.</small>