Hackers exploit Tencent app flaw to deploy GrayRabbit malware

September 13, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: bleepingcomputer.com

Threat Risk: High
Victim: Users of Sogou Input Method for Windows
Incident: Exploitation of CVE-2026-51990 to deploy the GrayRabbit backdoor via a crafted URI link.
Impact: Full remote code execution allowing the attacker to establish persistent access and steal system information.
Attacker: UNC3569
Analysis: The attack leverages a chain of three weaknesses: an unvalidated command-line argument in a custom URI, unrestricted URL navigation, and an outdated Chromium engine. By tricking users into clicking a crafted link, attackers bypass security controls to achieve remote code execution. This allows for the deployment of the GrayRabbit backdoor for espionage and data exfiltration.
Recommendations: Update Sogou Input Method to version 16.3.0.3498 or newer immediately.; Monitor for suspicious child processes spawning from biz_helper.exe or SGMyInput.exe.; Train users to avoid clicking unsolicited custom URI links in emails or messages.
Source: BleepingComputer

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *