VMTech
Discuss a project

Tencent patches Sogou Input Method flaw exploited by UNC3569

Tencent patches Sogou Input Method flaw exploited by UNC3569

Tencent has patched CVE-2026-51990 in Sogou Input Method for Windows after China-linked UNC3569 used the flaw to deploy the GRAYRABBIT backdoor. Gen Digital reported that a crafted link could take a victim from Sogou’s custom Windows protocol handler to attacker-controlled browser content and ultimately code execution with the privileges of the logged-in user.

The fix was delivered in Sogou Input Method version 16.3.0.3498. Gen said Tencent completed the fix within 12 days of its April 9, 2026 disclosure and pushed it through automatic updates on April 21. Google Threat Intelligence has tracked UNC3569 since 2021 and links it to China’s hacker-for-hire ecosystem.

Custom protocol handler opened the attack path

Sogou Input Method uses the sgbiz: custom link type to communicate between Windows components. Windows sends such links to biz_helper.exe, which identifies the requested Sogou component. Gen found that the handler validated the component name but did not filter command-line arguments supplied in the link.

Attackers directed the settings application, SGMyInput.exe, to open its skin store with an address they controlled. The skin store is the only area of that application that opens a browser window, and the supplied address was passed to that browser without validation. Gen said a victim clicking the crafted link was sufficient for the chain it observed.

Tencent characterised the attack as relatively complex and said social engineering would be needed to persuade a user to actively approve a browser pop-up prompt. Chromium-based browsers can request confirmation before passing a link to another local application, although neither Tencent nor Gen specified what victims saw in the campaign.

Old Chromium components increased the impact

The built-in browser is a customised Chromium 80 build dating from around March 2020. Gen found that its sandbox and web-security controls remained disabled in the code. The campaign exploited CVE-2021-38003, a V8 flaw in the handling of JSON.stringify that Google fixed in Chrome 95 in October 2021.

Without the browser sandbox, successful JavaScript exploitation can result in code execution under the user’s account without a separate browser escape. Gen noted that the patched Sogou files it examined still used Chromium 80 and retained the disabled sandbox and web-security settings. The update blocks externally supplied web addresses through the affected handler rather than modernising the browser engine.

GRAYRABBIT delivery and detection clues

The exploit downloaded a legitimate 7-Zip copy, a malicious DLL named 7z.dll, and an encrypted payload into C:\Users\Public\Documents. Launching 7-Zip caused DLL sideloading, after which the loader checked the running-process count, decrypted the payload and removed itself. Gen observed it using an NTFS alternate data stream before deletion, complicating disk-based inspection.

The resulting GRAYRABBIT backdoor provides a remote command shell, supports file transfers and can load extra modules from its server. Its observed command-and-control address was mail.uaiubifas[.]top on port 443, using RC4-scrambled plain TCP rather than TLS. Gen also named noht1ng[.]top as the exploit host and published hashes for the loader, encrypted payload and GRAYRABBIT.

Business implication

Organisations using Sogou Input Method should verify that version 16.3.0.3498 is installed, investigate systems exposed before the update, and use Gen’s indicators in endpoint and network hunts. Monitoring non-TLS traffic over port 443 can help identify the observed GRAYRABBIT communications, while the remaining legacy browser components warrant continued risk review.

#cybersecurity#windowssecurity#vulnerability#threatintel
Open analytics
On the site 0 views
min read 4 11.09.2026
Instagram

Tencent patches Sogou Input Method flaw exploited by UNC3569

Open the post on Instagram ↗