โ Back to Feed
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
CVE-2026-51990
September 13, 2026 ยท BleepingComputer ยท Severity: CRITICAL
A China-aligned espionage group is actively exploiting CVE-2026-51990, a critical flaw in Tencent applications, to deliver the GrayRabbit backdoor to systems across the Asia-Pacific region. The campaign leverages the widespread adoption of Tencent software to establish persistent access in targeted environments with minimal detection risk. ๐ **Analyst Note:** GrayRabbit continues to be the backdoor of choice for China-linked espionage groups, now expanding from Sogou IME exploitation to Tencent app vulnerabilities. The pattern of weaponizing trusted Chinese software is consistent and accelerating.
Key Takeaways
- China-aligned threat actors are actively exploiting CVE-2026-51990, a critical vulnerability in Tencent applications, to deploy the GrayRabbit backdoor malware on targeted systems throughout the Asia-Pacific region.
- The exploitation chain involves weaponizing a trusted Chinese software ecosystem component, demonstrating that supply chain trust in regional software vendors represents a significant and growing attack vector for espionage groups.
- Organizations operating in APAC markets should urgently audit their Tencent software deployments and monitor for anomalous process behavior associated with GrayRabbit backdoor activity patterns.