China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
ID: 7cfa1470-c7cd-5e1b-873c-83fd76492d38
STIX ID: report--7cfa1470-c7cd-5e1b-873c-83fd76492d38
Feed Name: The Hacker News
Threat Score
Gen Digital found that UNC3569 exploited a flaw in Sogou Input Method's Windows components—using a crafted sgbiz: link and an embedded Chromium 80 browser with sandboxing and same-origin protections disabled—to run a V8 exploit (CVE-2021-38003) and install the GRAYRABBIT backdoor; Tencent patched the link handler but the outdated Chromium engine remains unpatched. Indicators (SHA-256s, domains, IP, file paths) and mitigation (update to version 16.3.0.3498) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
