SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefMonday, September 14, 2026 INTEL CONFIDENCE 70% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Tencent Sogou Flaw Exploited to Deploy GrayRabbit | CRITICAL |
|
5 C2 IPs | 0 OTX IOCs | 5 ARTICLES |
|
■ ANALYST TLDR China-aligned cyber espionage actors are actively exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method to deploy the GrayRabbit backdoor on Windows systems. Concurrently, threat actors are leveraging sophisticated passkey-themed social engineering and abusing third-party email delivery infrastructure to hijack Microsoft Cloud accounts and exfiltrate sensitive data. Organizations must immediately audit their environments for unauthorized Chinese-language input software and reinforce cloud authentication mechanisms against advanced phishing techniques. |
|
■ CRITICAL STORIES Hackers exploit Tencent app flaw to deploy GrayRabbit malware A critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows is being actively exploited by a China-aligned espionage group to drop the GrayRabbit backdoor, highlighting the severe risk of localized software utilities in global enterprise networks. |
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data Threat actors are bypassing traditional defenses by utilizing passkey-themed social engineering and abusing third-party email delivery systems to compromise Microsoft Cloud environments and exfiltrate sensitive corporate data. |
Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI The NSA is rapidly restructuring to establish five new mission centers focusing on cyber and AI, reflecting the growing geopolitical and technological importance of these domains in national security. |
Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up Anthropic's CEO warns that rapid AI advancement could enable autonomous agent swarms capable of taking over internet infrastructure within 6 to 12 months if safety guardrails are not established. |
|
■ CVEs IDENTIFIED CVE-2026-51990 Tencent Sogou Input Method for Windows — Remote Code Execution and GrayRabbit Backdoor Deployment |
[CVE-TBD] Microsoft Cloud — Account Hijacking and Data Exfiltration via Passkey Phishing |
|
■ THREAT ACTORS China-aligned espionage group | Nation-State |
Exploiting CVE-2026-51990 in Tencent Sogou Input Method to deploy GrayRabbit backdoor. |
Unknown Threat Actor | Cybercrime / Espionage |
Executing passkey-themed social engineering campaigns to hijack Microsoft Cloud accounts. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Exploitation of CVE-2026-51990 in Tencent Sogou Input Method. |
| T1566.002 | | Phishing: Spearphishing Link | Passkey-themed social engineering emails used to hijack Microsoft Cloud accounts. |
| T1071.001 | | Application Layer Protocol: Web Protocols | GrayRabbit backdoor communication with command and control servers. |
| T1114 | | Email Collection | Exfiltration of data from compromised Microsoft Cloud environments. |
|
■ PATCH PRIORITY Tencent — Sogou Input Method for Windows (CVE-2026-51990) — Active exploitation to deploy GrayRabbit backdoor (RCE) — BC |
Microsoft — Microsoft Cloud — Passkey-themed phishing campaigns bypassing traditional MFA to hijack accounts — THN |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch CVE-2026-51990 immediately on all Windows hosts running Tencent Sogou Input Method to prevent GrayRabbit backdoor deployment. |
| 2 | [P2] Implement strict application control policies to audit and block unauthorized installations of Tencent Sogou Input Method in corporate environments. |
| 3 | [P2] Educate users on passkey-themed social engineering tactics and enforce FIDO2/WebAuthn-compliant multi-factor authentication to secure Microsoft Cloud accounts. |
| 4 | [P2] Monitor and restrict outbound traffic to unauthorized third-party email delivery infrastructures to mitigate phishing campaign delivery. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |