โ† Back to Feed

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

CVE-2026-51990

September 13, 2026 ยท BleepingComputer ยท Severity: CRITICAL

A China-aligned espionage group is actively exploiting CVE-2026-51990, a critical flaw in Tencent applications, to deliver the GrayRabbit backdoor to systems across the Asia-Pacific region. The campaign leverages the widespread adoption of Tencent software to establish persistent access in targeted environments with minimal detection risk. ๐Ÿ“Œ **Analyst Note:** GrayRabbit continues to be the backdoor of choice for China-linked espionage groups, now expanding from Sogou IME exploitation to Tencent app vulnerabilities. The pattern of weaponizing trusted Chinese software is consistent and accelerating.

Key Takeaways

  • China-aligned threat actors are actively exploiting CVE-2026-51990, a critical vulnerability in Tencent applications, to deploy the GrayRabbit backdoor malware on targeted systems throughout the Asia-Pacific region.
  • The exploitation chain involves weaponizing a trusted Chinese software ecosystem component, demonstrating that supply chain trust in regional software vendors represents a significant and growing attack vector for espionage groups.
  • Organizations operating in APAC markets should urgently audit their Tencent software deployments and monitor for anomalous process behavior associated with GrayRabbit backdoor activity patterns.
โ˜• Buy a Coffee