Popular Tencent typing app used to install espionage backdoor

Popular Tencent typing app used to install espionage backdoor. Windows users can be infected with the GrayRabbit backdoor after clicking a crafted link handled by Tencent’s Sogou Input Method.

Daily Cyber News: Popular Tencent typing app used to install espionage backdoor

Windows users can be infected with the GrayRabbit backdoor after clicking a crafted link handled by Tencent’s Sogou Input Method. A China-aligned espionage group is exploiting the weakness in the wild, and the app reportedly has hundreds of millions of installations in China. The attack combines unsafe command handling with an outdated Chromium 80 browser that runs without a sandbox.

Key context: A successful infection can support command execution, file transfers, system discovery, reverse shells, and in-memory plugins.

For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

Topics: cybersecurity news, cybersecurity, cyber risk, windows, Popular Tencent, Popular, Tencent, typing, used, install.

Popular Tencent typing app used to install espionage backdoor
Broadcast by