Sogou Input Method Vulnerability Enabled UNC3569 GRAYRABBIT Backdoor Deployment

Published:

A China-linked hacking group exploited a vulnerability in Sogou Input Method, a widely used tool for typing Chinese characters on Windows, to deploy the GRAYRABBIT backdoor on targeted systems, according to cybersecurity company Gen Digital. The company identified the flaw while investigating an active intrusion linked to UNC3569, a group that Google Threat Intelligence connects to China and has tracked since 2021. The group has previously targeted government, education, technology, and financial sectors, mainly across East and Southeast Asia. The attack began through a specially crafted link and allowed attackers to perform activities available to the logged-in user. Tencent, which owns and develops Sogou Input Method, addressed the vulnerability through an update released in April 2026.

Gen Digital reported that the exploited issue, tracked as CVE-2026-51990, affected the Windows version of Sogou Input Method and involved the way the application handled a custom Windows link type called sgbiz:. When a user opened an sgbiz: link, Windows forwarded the request to biz_helper.exe, a Sogou component responsible for processing the request and launching specific features. Gen found that the component checked which Sogou application should start but did not properly validate the command-line arguments passed through the link. This allowed attackers to control the parameters used by the application. The attackers directed the link toward SGMyInput.exe, a Sogou settings application, and instructed it to open the skin store feature using a web address controlled by them. Since the skin store was the only feature that opened a browser window, attackers used it to load a malicious webpage. Gen discovered that Sogou’s built-in browser relied on Chromium 80, an older version released around March 2020, and that key security protections, including the browser sandbox and same-origin policy, had been disabled. This allowed malicious scripts to execute code on the system with the same permissions as the logged-in user.

The attack chain used CVE-2021-38003, a vulnerability affecting Chrome’s V8 JavaScript engine related to JSON.stringify handling. Google fixed the issue in Chrome 95 in 2021, and CISA later added it to its catalog of known exploited vulnerabilities. However, Sogou’s embedded Chromium component did not receive the same security updates and continued using an outdated browser version. Gen noted that multiple V8 vulnerabilities fixed in later Chrome releases remained present in the Chromium version included with Sogou Input Method, although not every vulnerability was confirmed to be exploitable through the application. During the investigation, Gen found that the exploit delivered a downloader that retrieved multiple files from an Alibaba Cloud server located in Hong Kong. The files included a legitimate copy of 7-Zip, a malicious DLL, and an encrypted payload file. The attackers stored these files in a public Windows directory and used a technique where launching the legitimate 7-Zip application loaded the malicious code. The malware also checked the number of running processes before decrypting its payload, helping it avoid detection in automated security analysis environments that usually run fewer processes than real user systems.

The final payload deployed in the campaign was identified as GRAYRABBIT, a backdoor previously linked to UNC3569 activity. The malware provides attackers with remote command execution, file transfer capabilities, and the ability to load additional modules from attacker-controlled servers. Gen found that the backdoor communicated with its command server through port 443 using RC4-scrambled TCP traffic instead of standard TLS encryption. The company advised monitoring unusual communication patterns involving non-encrypted traffic over commonly used HTTPS ports. Tencent fixed the vulnerability after Gen reported it on April 9, 2026, and released the update through automatic distribution in Sogou Input Method version 16.3.0.3498. The update modified biz_helper.exe by restricting unauthorized web addresses, allowing only HTTPS links and checking approved domains. However, Gen noted that the embedded Chromium browser engine was not updated, meaning the application continued using an older browser component with certain security settings unchanged. Users are advised to install the latest Sogou Input Method update and review systems for signs of compromise, including unusual processes, suspicious files, and unexpected network activity associated with GRAYRABBIT infrastructure.

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img