bleeping-computer · Crawled Sep 13, 2026

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

1 Actors 1 Malware
Read original article ↗

AI Summary

Threat actors associated with the China-aligned UNC3569 group are actively exploiting a critical remote code execution vulnerability, CVE-2026-51990, in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. The attack chain begins with a maliciously crafted sgbiz: URI that triggers command-line argument injection, leading to unvalidated execution in the SGMyInput.exe process. This allows loading of an attacker-controlled URL in an outdated, unsandboxed Chromium-based webview, which then exploits known browser flaws to achieve code execution and deploy the modular GrayRabbit malware. The malware supports remote command execution, file transfers, reverse shells, and reflective plugin loading, with its C2 configuration RC4-encoded.

AI-extracted · verify before operational use

Extracted Entities 2 found

MITRE ATT&CK TTPs 7 techniques