CuraSec

Plan active

China-aligned APT exploits Sogou IME flaw to deploy GrayRabbit backdoor

2026-09-13 14:54 UTC · BleepingComputer · read the source ↗ #apt#windows#backdoor
  • Engineer — Skip
  • SOC/IR — Plan: A China-aligned espionage group is actively deploying the GrayRabbit backdoor via this campaign; audit endpoint inventory for Sogou IME presence and prepare GrayRabbit detection coverage before any confirmed exposure surfaces.
  • Leader — Skip
  • Signals: CVE-2026-51990 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.