Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » Sogou Input Method vulnerability weaponised to drop GrayRabbit backdoor
    Technology

    Sogou Input Method vulnerability weaponised to drop GrayRabbit backdoor

    Gary BehanBy Gary Behan20/09/2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    Sogou Input Method vulnerability
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    A Sogou Input Method vulnerability carrying the identifier CVE-2026-51990 is being actively exploited in the wild to install the GrayRabbit backdoor on Windows machines, according to researchers at Gen Digital. The flaw is a one-click remote code execution weakness, and the group behind the campaign is UNC3569, a threat actor with documented ties to the People’s Republic of China.

    How the Sogou Input Method vulnerability is exploited

    The attack chains three weaknesses in Sogou Input Method, a widely used application developed by Tencent that lets users type Chinese characters on a standard keyboard. Gen Digital’s research team, Gen Threat Labs, reports that the product exposes an unvalidated command-line argument injection through its sgbiz: URI handler, an unrestricted URL navigation path in its Chromium Embedded Framework (CEF) webview, and an outdated, unsandboxed Chromium 80 browser engine with key web-security protections disabled.

    The sequence begins when a victim clicks a crafted sgbiz: link. Windows hands that URI to Sogou’s biz_helper.exe protocol handler, which passes attacker-controlled command-line arguments directly to the legitimate SGMyInput.exe executable without any validation. Those injected arguments open Sogou’s skincenter component and instruct its embedded webview to load a URL of the attacker’s choosing, one Sogou makes no attempt to restrict by scheme or destination.

    From there, a malicious page exploits a known flaw in the outdated Chromium 80 engine. Because that browser runs without a sandbox and with important protections stripped out, the exploit achieves code execution and deposits GrayRabbit on the host.

    GrayRabbit’s capabilities and UNC3569’s profile

    GrayRabbit was first described as a modular malware family by Google researchers in 2024, who linked it to UNC3569. The sample analysed by Gen Threat Labs is a more mature 64-bit variant with an expanded command set. Its capabilities cover process execution, interactive reverse shells, file upload and download, system and user information harvesting, and reflective in-memory plugin loading. The configuration is RC4-encoded, and according to The Hacker News, the backdoor reaches its command-and-control server at mail.uaiubifas[.]top on port 443, though the traffic is plain TCP scrambled with RC4 rather than TLS, meaning it is dressed up to look like HTTPS without any of the encryption.

    The group operating it is documented in detail by Gen Digital as a PRC-nexus threat actor that prioritises operational efficiency, routinely targeting n-day vulnerabilities in widely deployed software and mixing custom-developed malware with commercial tooling. That combination (opportunistic exploitation of known flaws plus purpose-built implants) makes UNC3569 a persistent and adaptable threat rather than a group that burns zero-days on every operation.

    As Aviatrix noted in September 2026, the active exploitation of CVE-2026-51990 by UNC3569 placed this campaign squarely in the category of espionage-aligned, China-nexus operations rather than opportunistic cybercrime.

    The patch and what it leaves open

    Gen Threat Labs reported their findings to Tencent on 9 April. Tencent deployed a fix in Sogou Input Method version 16.3.0.3498, released on 21 April. The patch validates URL arguments accepted through the protocol handler, permits only HTTPS, and restricts navigation to domains associated with Sogou and Tencent.

    The caveat is a substantial one. Gen Threat Labs warned that the underlying browser engine remains outdated and still runs without a sandbox, with many web-security protections disabled. The fix closes the specific attack path UNC3569 used, but the structural weakness that made exploitation straightforward in the first place, an uncontained, antiquated Chromium embedded in a consumer application with hundreds of millions of installations in China, has not been addressed.

    Users running Sogou Input Method should update to version 16.3.0.3498 or later immediately, given the scale of the install base and the group’s documented habit of returning to the same software until a target is reached.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleDutch NCSC warns Check Point VPN flaws carry near-certain attack risk
    Next Article Revolut Data Breach: Fake Government Request Fools Company Into Handing Over Passports and Transaction Records
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    Vite Dev Server Exploit Hits 800+ Attacks, Targeting AWS and Azure Credentials

    21/09/2026

    September 2026 RDS Failures Hit Windows Server After Patch Tuesday

    21/09/2026

    Revolut Data Breach: Fake Government Request Fools Company Into Handing Over Passports and Transaction Records

    21/09/2026

    Dutch NCSC warns Check Point VPN flaws carry near-certain attack risk

    20/09/2026

    Claude AI Threat Intelligence Report Exposes ShinyHunters, Midnight Blizzard and Chinese Espionage

    20/09/2026

    Microsoft 365 Passkey Phishing Campaign Tied to ShinyHunters and Helix Gangs

    19/09/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.