Skip to main content
TencentCybersecurity incident

A critical vulnerability, CVE-2026-51990, in Tencent's Sogou Input Method for Windows is being actively exploited by a China-aligned espionage group to deploy the GrayRabbit backdoor malware.

What happened

Post: "Hackers exploit Tencent app flaw to deploy GrayRabbit malware"

Source

RedditSep 13, 2026By u/falconupkid

r/SecOpsDaily

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

upvotes
3
comments
0

Post

Highlighted: the lines this signal was extracted from

Threat actors linked to a China-aligned espionage group are actively exploiting CVE-2026-51990, a critical vulnerability in Tencent’s Sogou Input Method for Windows, to deploy the GrayRabbit backdoor. This is a targeted campaign, not a broad spray-and-pray operation. TTPs (MITRE): Initial access via exploitation of a public-facing application (T1190). The vulnerability allows for privilege escalation or code execution within the input method’s context. Persistence is achieved via the GrayRabbit backdoor, which likely establishes C2 communications. IOCs: No specific hashes or IPs have been published at this time. The primary indicator is the presence of the Sogou Input Method (a common application in Chinese-speaking environments) and subsequent anomalous network traffic from the host. Affected Versions: All versions of Sogou Input Method for Windows prior to the latest patch released on 2026-03-10. Defense: Immediately update Sogou Input Method to the latest patched version. Monitor for unusual outbound connections from hosts running this software, particularly to non-standard ports or known adversary infrastructure. EDR rules should flag any process spawning from the input method’s executable (SogouTSF.exe or similar) that attempts to execute cmd.exe, powershell.exe, or write to %APPDATA% or %TEMP%. Source...

Keep reading with a free account

The rest of this post, and every signal for Tencent, is in your free account.

Extracted by Autobound

From the Signal API record
Signal
Cybersecurity incident

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/SecOpsDaily
Stage
Confirmed
Event date
Sep 2026

The full record

From the Signal API record

Numbers

Mentions
2

Details

Timing
In progress
Category
Active exploitation
Virality
Very low
Post kind
Multi media
Prominence
Core
Company's role
Subject
Signal category
Event

Topics and mentions

Topics

  • cybersecurity
  • vulnerability
  • active exploitation
  • espionage
  • malware

Flair

  • NEWS

Products named

  • Sogou Input Method for Windows

Extraction

Sentiment
Negative
Detected
Sep 13, 2026
signal_type
reddit-company
signal_subtype
cybersecurityIncident

Use this data

Get every Reddit signal for Tencent and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Tencent this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/94a7ef78-7a19-5183-af86-b81f39627892 returns this record as JSON. POST /v1/companies/enrich returns every signal for tencent.com.

{
  "signal_id": "94a7ef78-7a19-5183-af86-b81f39627892",
  "signal_type": "reddit-company",
  "signal_subtype": "cybersecurityIncident",
  "detected_at": "2026-09-13T15:03:30+00:00",
  "company": {
    "name": "Tencent",
    "domain": "tencent.com"
  },
  "data": {
    "nsfw": false,
    "stage": "confirmed",
    "awards": 0,
    "timing": "in_progress",
    "topics": [
      "cybersecurity",
      "vulnerability",
      "active exploitation",
      "malware",
      "espionage"
    ],
    "post_id": "1wfa39o",
    "summary": "A critical vulnerability, CVE-2026-51990, in Tencent's Sogou Input Method for Windows is being actively exploited by a China-aligned espionage group to deploy the GrayRabbit backdoor malware.",
    "category": "active_exploitation",
    "evidence": [
      "[post] Threat actors linked to a China-aligned espionage group are actively exploiting CVE-2026-51990, a critical vulnerability in Tencent’s Sogou Input Method for Windows, to deploy the GrayRabbit backdoor.",
      "[post] The vulnerability allows for privilege escalation or code execution within the input method’s context.",
      "[post] Affected Versions: All versions of Sogou Input Method for Windows prior to the latest patch released on 2026-03-10."
    ],
    "virality": "very_low",
    "post_date": "2026-09-13T15:03:30.000Z",
    "post_kind": "multi_media",
    "post_text": "Threat actors linked to a China-aligned espionage group are actively exploiting CVE-2026-51990, a critical vulnerability in Tencent’s Sogou Input Method for Windows, to deploy the GrayRabbit backdoor. This is a targeted campaign, not a broad spray-and-pray operation.\n\nTTPs (MITRE): Initial access via exploitation of a public-facing application (T1190). The vulnerability allows for privilege escalation or code execution within the input method’s context. Persistence is achieved via the GrayRabbit backdoor, which likely establishes C2 communications.\n\nIOCs: No specific hashes or IPs have been published at this time. The primary indicator is the presence of the Sogou Input Method (a common application in Chinese-speaking environments) and subsequent anomalous network traffic from the host.\n\nAffected Versions: All versions of Sogou Input Method for Windows prior to the latest patch released on 2026-03-10.\n\nDefense: Immediately update Sogou Input Method to the latest patched version. Monitor for unusual outbound connections from hosts running this software, particularly to non-standard ports or known adversary infrastructure. EDR rules should flag any process spawning from the input method’s executable (SogouTSF.exe or similar) that attempts to execute cmd.exe, powershell.exe, or write to %APPDATA% or %TEMP%.\n\nSource...",
    "sentiment": "negative",
    "subreddit": "SecOpsDaily",
    "event_date": "2026-09",
    "post_flair": [
      "NEWS"
    ],
    "post_title": "Hackers exploit Tencent app flaw to deploy GrayRabbit malware",
    "prominence": "core",
    "source_url": "https://www.reddit.com/r/SecOpsDaily/comments/1wfa39o/hackers_exploit_tencent_app_flaw_to_deploy/",
    "entity_role": "subject",
    "post_author": "falconupkid",
    "upvote_ratio": 1,
    "mention_count": 2,
    "mention_surge": false,
    "subreddit_url": "https://www.reddit.com/r/SecOpsDaily/",
    "total_upvotes": 3,
    "comments_total": 0,
    "total_comments": 0,
    "event_date_text": "actively",
    "post_author_url": "https://www.reddit.com/user/falconupkid/",
    "signal_category": "event",
    "comments_included": 0,
    "products_mentioned": [
      "Sogou Input Method for Windows"
    ]
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.