Plan
active
China-aligned APT exploits Sogou IME flaw to deploy GrayRabbit backdoor
- Engineer — Skip
- SOC/IR — Plan: A China-aligned espionage group is actively deploying the GrayRabbit backdoor via this campaign; audit endpoint inventory for Sogou IME presence and prepare GrayRabbit detection coverage before any confirmed exposure surfaces.
- Leader — Skip
- Signals: CVE-2026-51990 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.