Skip to content
China-linked UNC3569 Exploits Sogou Input Method Flaw to Deploy GrayRabbit Malware

China-linked UNC3569 Exploits Sogou Input Method Flaw to Deploy GrayRabbit Malware

First seen 13 Sep 2026, 15:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 13, 2026 at 15:57 UTC
  • UNC3569 exploited a critical vulnerability in Sogou Input Method to deploy GrayRabbit malware.
  • The attack utilizes a crafted link for remote code execution via unvalidated command-line arguments.
  • Tencent patched the vulnerability, but the underlying browser remains outdated and unsandboxed.

A China-linked hacking group, UNC3569, exploited a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. The attack involved a crafted link that allowed remote code execution, enabling attackers to control the victim's machine. Sogou Input Method is widely used in China, with hundreds of millions of installations. The vulnerability was reported by Gen Digital, which noted that the flaw involves unvalidated command-line arguments and an outdated Chromium browser engine. Tencent released a patch on April 21, 2026, but the underlying browser remains outdated and unsandboxed. The attack chain leverages multiple weaknesses in the application, making it a significant threat to users. The backdoor, GrayRabbit, has been linked to espionage activities and has capabilities for extensive control over infected systems. As of now, the exploit is confirmed to be actively exploited in the wild.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2021-11-03
CVE-2021-38003 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2026-04-09
Vulnerability reported to Tencent
Gen Digital informed Tencent about the critical vulnerability in Sogou Input Method.
Bleepingcomputer
2026-04-21
Patch released by Tencent
Tencent released a patch for Sogou Input Method version 16.3.0.3498 to address the vulnerability.
Bleepingcomputer
2026-09-11
Gen Digital publishes research
Gen Digital published findings on the exploitation of the Sogou Input Method by UNC3569.
Thehackernews
2026-09-11
Public exploit for CVE-2026-51990 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-09-13
BleepingComputer reports on ongoing exploitation
BleepingComputer confirmed that the vulnerability is actively exploited in the wild by UNC3569.
Bleepingcomputer

More articles in this cluster (2)

Following this threat?

Track Unc3569, Grayrabbit and Gen Digital in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed