logo

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

ID: 7cfa1470-c7cd-5e1b-873c-83fd76492d38

STIX ID: report--7cfa1470-c7cd-5e1b-873c-83fd76492d38

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-09-11

Date Updated: 2026-09-11

Author: [email protected] (The Hacker News)

...
...

Gen Digital found that UNC3569 exploited a flaw in Sogou Input Method's Windows components—using a crafted sgbiz: link and an embedded Chromium 80 browser with sandboxing and same-origin protections disabled—to run a V8 exploit (CVE-2021-38003) and install the GRAYRABBIT backdoor; Tencent patched the link handler but the outdated Chromium engine remains unpatched. Indicators (SHA-256s, domains, IP, file paths) and mitigation (update to version 16.3.0.3498) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.