China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
Reported exploitedSogou Input MethodUNC3569Our summary
Security researchers at Gen Digital disclosed that China-linked threat actor UNC3569 leveraged a vulnerability in the Windows version of Sogou Input Method to install the GRAYRABBIT backdoor on victim systems. The attack chain involved manipulating an unvalidated sgbiz link handler to execute a JavaScript exploit for CVE-2021-38003 within Sogou's outdated Chromium 80 browser engine, which had sandboxing disabled. Although Tencent issued a patch for this issue, tracked as CVE-2026-51990, in version 16.3.0.3498, the underlying browser engine remains vulnerable due to its age and lack of modern security controls.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.