Popular Tencent typing app used to install espionage backdoor

Popular Tencent typing app used to install espionage backdoor. Windows users can be infected with the GrayRabbit backdoor after clicking a crafted link handled by Tencent’s Sogou Input Method.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Monday, September 14th, 2026.

Windows users can be infected with the GrayRabbit backdoor after clicking a crafted link handled by Tencent’s Sogou Input Method. A China-aligned espionage group is exploiting the weakness in the wild, and the app reportedly has hundreds of millions of installations in China. The attack combines unsafe command handling with an outdated Chromium 80 browser that runs without a sandbox. Tencent fixed the link-handling issue in version 16.3.0.3498, but researchers warned that the embedded browser remains outdated and weakly protected.

A successful infection can support command execution, file transfers, system discovery, reverse shells, and in-memory plugins. For leaders, this shows how widely installed utility software can become a strategic access path across a workforce. Defenders should update Sogou, inventory affected Windows endpoints, and investigate crafted-link activity or unexpected backdoor behavior. The attack still requires one click, but familiar software can make the lure more credible. It also shows why patching one entry point may not resolve deeper architectural weakness. Deploy version 16.3.0.3498 and closely monitor endpoints that continue using Sogou.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Popular Tencent typing app used to install espionage backdoor
Broadcast by