A China-linked hacking group exploited a critical vulnerability in the widely used Sogou Input Method to install the GRAYRABBIT backdoor on Windows computers, according to security firm Gen Digital.
Key Points
- The hacking group UNC3569 used a malicious link to trigger a flaw in Sogou’s custom link handler, bypassing security checks to execute arbitrary code.
- Sogou’s software utilized an outdated 2020 version of the Chromium browser engine with its sandbox and security protections intentionally disabled.
- The attack deployed the GRAYRABBIT backdoor, which provides attackers with a remote command shell and the ability to exfiltrate files from compromised systems.
- Tencent released a patch in April 2026 (version 16.3.0.3498) that restricts the types of web addresses the application can open, though the underlying browser engine remains outdated.
- Researchers identified the attack while investigating intrusions targeting government, finance, and technology sectors across East and Southeast Asia.