← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

🔄 Updated 36m ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • UNC3569 exploited a flaw in Sogou Input Method for Windows.
  • The attack deployed the GRAYRABBIT backdoor.
  • Tencent, Sogou's owner, fixed the flaw in April 2026.
  • Sogou Input Method has over 455 million monthly users.

Sogou Input Method Vulnerability Exploited

Security firm Gen Digital reported that the China-linked hacking group UNC3569 exploited a vulnerability in Sogou Input Method, a popular Chinese character input tool for Windows. The flaw allowed the group to install a backdoor on victims' machines, enabling remote command execution and file transfer capabilities.

GRAYRABBIT Backdoor Deployment

The attack began with a crafted link that, when opened, leveraged the vulnerability to install GRAYRABBIT, a backdoor used by UNC3569 for years. GRAYRABBIT provides attackers with a remote command shell and the ability to load additional modules, serving as an initial foothold on compromised systems.

UNC3569's Targeting and Scope

Google Threat Intelligence identifies UNC3569 as a China-linked hacker-for-hire group active since 2021. The group has targeted government, education, technology, and finance sectors, primarily in East and Southeast Asia. Sogou Input Method's widespread use, with over 455 million monthly users globally, made it an attractive target.

The Technical Flaw

The vulnerability resided in how Sogou Input Method handles custom sgbiz: links. The biz_helper.exe component, responsible for processing these links, failed to filter command-line arguments passed to other Sogou components. This allowed attackers to specify arbitrary arguments, leading to code execution. Tencent, the developer of Sogou, issued a fix for this specific flaw in April 2026.

Unchanged Underlying Issues

Despite the fix, Gen Digital noted that the patched version of Sogou Input Method still uses an outdated 2020 browser engine with its sandbox disabled. This indicates that while the specific exploitation vector was addressed, underlying security hygiene issues within the application persist.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~16 min · 14 stories · Sep 10

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A China-linked hacking group, UNC3569, exploited a vulnerability in Sogou Input Method for Windows to install the GRAYRABBIT backdoor on victim computers. The flaw allowed attackers to execute arbitrary commands, impacting users primarily in East and Southeast Asia.