Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Reported exploitedSogou Input MethodUNC3569Our summary
China-linked threat group UNC3569 is actively exploiting a critical one-click remote code execution vulnerability, identified as CVE-2026-51990, within Tencent's Sogou Input Method for Windows. By chaining multiple weaknesses in the application's custom URI handling and outdated embedded Chromium browser, attackers successfully install the GrayRabbit backdoor on victim systems.
Gen Threat Labs confirmed the campaign involves executing malicious commands through an unvalidated sgbiz: link, which ultimately bypasses security controls due to the lack of sandboxing in the bundled browser engine. While Tencent released a patch in version 16.3.0.3498 that restricts URL schemes to HTTPS and approved domains, the underlying outdated browser architecture remains vulnerable.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.