AUTO-UPDATED

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

A China-linked hacking group exploited a critical vulnerability in the widely used Sogou Input Method to install the GRAYRABBIT backdoor on Windows computers, according to security firm Gen Digital.

Key Points

  • The hacking group UNC3569 used a malicious link to trigger a flaw in Sogou’s custom link handler, bypassing security checks to execute arbitrary code.
  • Sogou’s software utilized an outdated 2020 version of the Chromium browser engine with its sandbox and security protections intentionally disabled.
  • The attack deployed the GRAYRABBIT backdoor, which provides attackers with a remote command shell and the ability to exfiltrate files from compromised systems.
  • Tencent released a patch in April 2026 (version 16.3.0.3498) that restricts the types of web addresses the application can open, though the underlying browser engine remains outdated.
  • Researchers identified the attack while investigating intrusions targeting government, finance, and technology sectors across East and Southeast Asia.

Why it Matters

This incident highlights the significant security risks posed by software that embeds outdated, unpatched browser components with disabled security features. Because Sogou Input Method is used by over 455 million people, such vulnerabilities provide a massive, high-value attack surface for state-sponsored actors to gain persistent access to sensitive enterprise and government networks.
Internet Published by info@thehackernews.com (The Hacker News)
Read original