← All stories
● Covered by 3 sources · 3 reportsMedium impact2 negative1 neutral

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

🔄 Updated 18d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • UNC3569 exploited a flaw in Sogou Input Method for Windows.
  • The attack deployed the GRAYRABBIT backdoor.
  • Tencent, Sogou's owner, fixed the flaw in April 2026.
  • Sogou Input Method has over 455 million monthly users.
  • The flaw is CVE-2026-51990.
  • The flaw is a one-click remote code execution vulnerability.
  • The attack uses unvalidated command-line arguments, unrestricted URL navigation, and an outdated Chromium engine.
  • The attack starts with a crafted sgbiz: custom URI.
  • Gen Threat Labs reported on the vulnerability.

Sogou Input Method Vulnerability Exploited

Security firm Gen Digital reported that the China-linked hacking group UNC3569 exploited a vulnerability in Sogou Input Method, a popular Chinese character input tool for Windows. The flaw allowed the group to install a backdoor on victims' machines, enabling remote command execution and file transfer capabilities.

GRAYRABBIT Backdoor Deployment

The attack began with a crafted link that, when opened, leveraged the vulnerability to install GRAYRABBIT, a backdoor used by UNC3569 for years. GRAYRABBIT provides attackers with a remote command shell and the ability to load additional modules, serving as an initial foothold on compromised systems.

UNC3569's Targeting and Scope

Google Threat Intelligence identifies UNC3569 as a China-linked hacker-for-hire group active since 2021. The group has targeted government, education, technology, and finance sectors, primarily in East and Southeast Asia. Sogou Input Method's widespread use, with over 455 million monthly users globally, made it an attractive target.

The Technical Flaw

The vulnerability resided in how Sogou Input Method handles custom sgbiz: links. The biz_helper.exe component, responsible for processing these links, failed to filter command-line arguments passed to other Sogou components. This allowed attackers to specify arbitrary arguments, leading to code execution. Tencent, the developer of Sogou, issued a fix for this specific flaw in April 2026.

Unchanged Underlying Issues

Despite the fix, Gen Digital noted that the patched version of Sogou Input Method still uses an outdated 2020 browser engine with its sandbox disabled. This indicates that while the specific exploitation vector was addressed, underlying security hygiene issues within the application persist.

Updates

🕒 2026-09-14 · new reporting from SecurityWeek
  • Gen Threat Labs reported on the vulnerability.
🕒 2026-09-13 · new reporting from BleepingComputer
  • The flaw is CVE-2026-51990.
  • The flaw is a one-click remote code execution vulnerability.
  • The attack uses unvalidated command-line arguments, unrestricted URL navigation, and an outdated Chromium engine.
  • The attack starts with a crafted sgbiz: custom URI.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method, a popular Chinese-language IME, has been actively exploited by the Chinese threat actor UNC3569. The exploit allows one-click code execution and has been used to deploy the GrayRabbit backdoor, impacting hundreds of millions of users.

A China-aligned espionage group, UNC3569, is actively exploiting a critical one-click remote code execution vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows. The exploit chain deploys the GrayRabbit backdoor by leveraging unvalidated command-line arguments, unrestricted URL navigation, and an outdated Chromium engine, impacting hundreds of millions of users in China.

A China-linked hacking group, UNC3569, exploited a vulnerability in Sogou Input Method for Windows to install the GRAYRABBIT backdoor on victim computers. The flaw allowed attackers to execute arbitrary commands, impacting users primarily in East and Southeast Asia.