Security firm Gen Digital reported that the China-linked hacking group UNC3569 exploited a vulnerability in Sogou Input Method, a popular Chinese character input tool for Windows. The flaw allowed the group to install a backdoor on victims' machines, enabling remote command execution and file transfer capabilities.
The attack began with a crafted link that, when opened, leveraged the vulnerability to install GRAYRABBIT, a backdoor used by UNC3569 for years. GRAYRABBIT provides attackers with a remote command shell and the ability to load additional modules, serving as an initial foothold on compromised systems.
Google Threat Intelligence identifies UNC3569 as a China-linked hacker-for-hire group active since 2021. The group has targeted government, education, technology, and finance sectors, primarily in East and Southeast Asia. Sogou Input Method's widespread use, with over 455 million monthly users globally, made it an attractive target.
The vulnerability resided in how Sogou Input Method handles custom sgbiz: links. The biz_helper.exe component, responsible for processing these links, failed to filter command-line arguments passed to other Sogou components. This allowed attackers to specify arbitrary arguments, leading to code execution. Tencent, the developer of Sogou, issued a fix for this specific flaw in April 2026.
Despite the fix, Gen Digital noted that the patched version of Sogou Input Method still uses an outdated 2020 browser engine with its sandbox disabled. This indicates that while the specific exploitation vector was addressed, underlying security hygiene issues within the application persist.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A China-linked hacking group, UNC3569, exploited a vulnerability in Sogou Input Method for Windows to install the GRAYRABBIT backdoor on victim computers. The flaw allowed attackers to execute arbitrary commands, impacting users primarily in East and Southeast Asia.