Daily Security Intel

Archives
Log in
Subscribe
September 14, 2026

[SecurityIntel] 14 Sep | Tencent Sogou Flaw Exploited to Deploy GrayRabbit

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Monday, September 14, 2026

INTEL CONFIDENCE  70%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Tencent Sogou Flaw Exploited to Deploy GrayRabbit

CRITICAL

5

C2 IPs

0

OTX IOCs

5

ARTICLES

■ ANALYST TLDR

China-aligned cyber espionage actors are actively exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method to deploy the GrayRabbit backdoor on Windows systems. Concurrently, threat actors are leveraging sophisticated passkey-themed social engineering and abusing third-party email delivery infrastructure to hijack Microsoft Cloud accounts and exfiltrate sensitive data. Organizations must immediately audit their environments for unauthorized Chinese-language input software and reinforce cloud authentication mechanisms against advanced phishing techniques.

■ CRITICAL STORIES

CRITICAL#1

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

A critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows is being actively exploited by a China-aligned espionage group to drop the GrayRabbit backdoor, highlighting the severe risk of localized software utilities in global enterprise networks.

HIGH#2

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Threat actors are bypassing traditional defenses by utilizing passkey-themed social engineering and abusing third-party email delivery systems to compromise Microsoft Cloud environments and exfiltrate sensitive corporate data.

INFO#3

Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI

The NSA is rapidly restructuring to establish five new mission centers focusing on cyber and AI, reflecting the growing geopolitical and technological importance of these domains in national security.

INFO#4

Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up

Anthropic's CEO warns that rapid AI advancement could enable autonomous agent swarms capable of taking over internet infrastructure within 6 to 12 months if safety guardrails are not established.

■ CVEs IDENTIFIED

CVE-2026-51990

Tencent Sogou Input Method for Windows — Remote Code Execution and GrayRabbit Backdoor Deployment

Critical

[CVE-TBD]

Microsoft Cloud — Account Hijacking and Data Exfiltration via Passkey Phishing

High

■ THREAT ACTORS

China-aligned espionage group

Nation-State

Exploiting CVE-2026-51990 in Tencent Sogou Input Method to deploy GrayRabbit backdoor.

Unknown Threat Actor

Cybercrime / Espionage

Executing passkey-themed social engineering campaigns to hijack Microsoft Cloud accounts.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Exploitation of CVE-2026-51990 in Tencent Sogou Input Method.
T1566.002
Phishing: Spearphishing Link | Passkey-themed social engineering emails used to hijack Microsoft Cloud accounts.
T1071.001
Application Layer Protocol: Web Protocols | GrayRabbit backdoor communication with command and control servers.
T1114
Email Collection | Exfiltration of data from compromised Microsoft Cloud environments.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Tencent — Sogou Input Method for Windows (CVE-2026-51990) — Active exploitation to deploy GrayRabbit backdoor (RCE) — BC

[P2 PATCH NOW]≤72h

Microsoft — Microsoft Cloud — Passkey-themed phishing campaigns bypassing traditional MFA to hijack accounts — THN

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch CVE-2026-51990 immediately on all Windows hosts running Tencent Sogou Input Method to prevent GrayRabbit backdoor deployment.
2[P2] Implement strict application control policies to audit and block unauthorized installations of Tencent Sogou Input Method in corporate environments.
3[P2] Educate users on passkey-themed social engineering tactics and enforce FIDO2/WebAuthn-compliant multi-factor authentication to secure Microsoft Cloud accounts.
4[P2] Monitor and restrict outbound traffic to unauthorized third-party email delivery infrastructures to mitigate phishing campaign delivery.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 15 Sep | Red Heron Exploits Gitea RCE Internationally Older → [SecurityIntel] 11 Sep | AI-driven agents and zero-days fuel global exploitation.
Powered by Buttondown, the easiest way to start and grow your newsletter.