INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
China-Linked UNC3569 Exploits Sogou Input Method Flaw for GRAYRABBIT
| 2026-09-11 07:56 HIGH HIGH EXPLOITED VULNERABILITY MALWARE & BOTNETS STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor called GRAYRABBIT on victims' computers. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns and develops Sogou, fixed the flaw in April 2026. Gen Digital found the flaw while investigating a live intrusion by UNC3569, a group that Google Threat Intelligence ties to China and places in the country's hacker-for-hire scene. The attack affected an estimated 455 million people per month across Windows, Android, and iOS users of Sogou Input Method, with over 70% of those users being from China. The backdoor installed by the attackers gave them a remote command shell, allowed files to be moved in both directions, and could load additional modules from their server at any time.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2021-38003, CVE-2026-51990 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
• User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures.
• Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
749160••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
d7a3c7••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
29c7ee••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
no•••••.top
ma•••••.top
7z•••••.dll
co•••••.dll
ch•••••.html
bi•••••.exe
8.218.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2021-38003CVE-2021-38003
CVE-2026-51990CVE-2026-51990
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
APAC
APAC
educationeducation
technologytechnology
governmentgovernment
financefinance
Incident Timeline
around March 2020
Threat actors exploited a vulnerability in Sogou's custom version of Chromium, built around March 2020, to deploy the GRAYRABBIT backdoor.
Click on any entity below to view its context and source!
organisation
Chromium
Sogou builds its own copy of Chromium, and it's version 80, from around March 2020.
October 2021
Google fixed a vulnerability in Chrome 95, specifically the Sogou input method flaw, which was exploited by China-linked threat actors to deploy the GRAYRABBIT backdoor.
Click on any entity below to view its context and source!
general_metric
95 Chrome
Google fixed it in Chrome 95 in October 2021.
November 3, 2021
Threat actors exploited the Sogou input method flaw to deploy the GRAYRABBIT backdoor, which was later added to CISA's catalog of known vulnerabilities.
December 2022
Threat actors exploited a Sogou input method flaw to deploy the GRAYRABBIT backdoor, which was later analyzed and publicly disclosed by Singapore firm STAR Labs in December 2022.
Click on any entity below to view its context and source!
target_region
Singapore
Singapore firm STAR Labs published a
full analysis and working exploit code
in December 2022.
organisation
STAR Labs
Singapore firm STAR Labs published a
full analysis and working exploit code
in December 2022.
April 9, 2026
Tencent fixed a vulnerability in Sogou's input method, tracked as CVE-2026-51990, which was exploited by China-linked threat actors to deploy the GRAYRABBIT backdoor.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-51990
What Tencent Fixed, and What It Left
Gen reported the flaw to Tencent on April 9, 2026, and it is tracked as CVE-2026-51990.
organisation
Tencent Fixed
What Tencent Fixed, and What It Left
Gen reported the flaw to Tencent on April 9, 2026, and it is tracked as CVE-2026-51990.
April 2026
Threat actors exploited a vulnerability in Sogou's input method to deploy the GRAYRABBIT backdoor, which was later patched by Tencent.
April 21, 2026
Tencent automatically updated all users to version 16.3.0.3498 on April 21, 2026, after discovering and patching the Sogou input method flaw exploited by China-linked threat actors for GRAYRABBIT backdoor deployment.
Click on any entity below to view its context and source!
infrastructure
16.3.0
The fix is in version 16.3.0.3498, which Gen says Tencent pushed to all users by automatic update on April 21, 2026.
April 21
The vulnerability in Sogou's input method was patched on April 21 with an automatic update, version 16.3.0.3498, which would be distributed to all users by Tencent.
Click on any entity below to view its context and source!
infrastructure
16.3.0
Tencent replied the next day and confirmed on April 21 that a fix was complete and would go out to all users via an automatic update in version 16.3.0.3498.
2026/09/11
A China-linked hacking group exploited a flaw in Sogou Input Method to install the GRAYRABBIT backdoor on victims' computers.
Click on any entity below to view its context and source!
organisation
Deploy GRAYRABBIT Backdoor
China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor.
infrastructure
Windows
A China-linked hacking group exploited a flaw in
Sogou Input Method
, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in
research published Thursday
.
That research put its user base at more than 455 million people a month across Windows, Android and iOS, and its share of Chinese input-method users at about 70%.
The flaw Gen found is in the Windows version.
It is a set of components that communicate with each other via a custom link type registered on Windows, sgbiz:.
When anything opens an sgbiz: link, Windows passes it to biz_helper.exe, which reads the link and starts the Sogou component it names.
infrastructure
Android
That research put its user base at more than 455 million people a month across Windows, Android and iOS, and its share of Chinese input-method users at about 70%.
infrastructure
Ios
That research put its user base at more than 455 million people a month across Windows, Android and iOS, and its share of Chinese input-method users at about 70%.
organisation
the University of Toronto
How One Link Reached the Machine
Sogou Input Method is the most popular Chinese input method in China, according to 2023 research by Citizen Lab at the University of Toronto.
organisation
DLL
Gen traced it pulling three files from a server on Alibaba Cloud in Hong Kong: a legitimate copy of 7-Zip, a malicious DLL, and an encrypted file holding the final payload.
infrastructure
7 Zip
Gen traced it pulling three files from a server on Alibaba Cloud in Hong Kong: a legitimate copy of 7-Zip, a malicious DLL, and an encrypted file holding the final payload.
The malicious DLL was saved under the name 7-Zip loads from its own folder at startup, so running 7-Zip loaded the attacker's code instead.
Its only job was to start 7-Zip.
organisation
IP
8.218.50[.]207
…2e encrypted payload file, named p
SHA-256
d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor, internal name core.dll
Domain
mail.uaiubifas[.]top backdoor command server, port 443
Domain
noht1ng[.]top hosted the exploit page
IP
8.218.50[.]207 staging server, Alibaba Cloud Hong Kong
Path
C:\Users\Public\Documents\ where the three files were written
organisation
Path
…2e encrypted payload file, named p
SHA-256
d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor, internal name core.dll
Domain
mail.uaiubifas[.]top backdoor command server, port 443
Domain
noht1ng[.]top hosted the exploit page
IP
8.218.50[.]207 staging server, Alibaba Cloud Hong Kong
Path
C:\Users\Public\Documents\ where the three files were written
organisation
TCP
The backdoor reaches its server at mail.uaiubifas[.]top on port 443, and the traffic there is plain TCP scrambled with RC4 rather than TLS.
organisation
Domain
mail.uaiubifas[.]top backdoor command
…719cf72e483595c6aad718efa74d675a98662e02422e encrypted payload file, named p
SHA-256
d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor, internal name core.dll
Domain
mail.uaiubifas[.]top backdoor command server, port 443
Domain
noht1ng[.]top hosted the exploit page
IP
8.218.50[.]207 staging server, Alibaba Cloud Hong Kong
Path
C:\Users\Public\Doc…
organisation
Domain
…719cf72e483595c6aad718efa74d675a98662e02422e encrypted payload file, named p
SHA-256
d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor, internal name core.dll
Domain
mail.uaiubifas[.]top backdoor command server, port 443
Domain
noht1ng[.]top hosted the exploit page
IP
8.218.50[.]207 staging server, Alibaba Cloud Hong Kong
Path
C:\Users\Public\Doc…
infrastructure
443 Domain
SHA-256
29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 malicious DLL loader, written to disk as 7z.dll
SHA-256
749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e encrypted payload file, named p
SHA-256
d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor, internal name core.dll
Domain
mail.uaiubifas[.]top backdoor command s…
organisation
Chrome
Why a 2021 Browser Bug Still Worked
The page the victims were sent to carried an exploit for
CVE-2021-38003
, a flaw in how V8, Chrome's JavaScript engine, handled JSON.stringify.
organisation
JSON.stringify
Why a 2021 Browser Bug Still Worked
The page the victims were sent to carried an exploit for
CVE-2021-38003
, a flaw in how V8, Chrome's JavaScript engine, handled JSON.stringify.
organisation
Google
The backdoor it installed is
GRAYRABBIT
, a small program the group has used for years and that Google describes as its first step onto a machine.
organisation
Tencent
Tencent's fix blocked the way in.
organisation
The Hacker News
The Hacker News checked each flaw's CVE record against that version.
organisation
NTFS
Gen found it moving its own contents into an NTFS alternate data stream, a hidden part of the file record, and then marking the file for deletion.
organisation
qq.com
It now looks for the two arguments that carry web addresses, rejects anything that is not HTTPS, and checks the hostname against four allowed endings: sogou.com, qq.com, woa.com and sogou.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
A China-linked hacking group exploited a flaw in
Sogou Input Method
, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in
research published Thursday
.
That research put its user base at more than 455 million people a month across Windows, Android and iOS, and its share of Chinese input-method users at about 70%.
The flaw Gen found is in the Windows version.
It is a set of components that communicate with each other via a custom link type registered on Windows, sgbiz:.
When anything opens an sgbiz: link, Windows passes it to biz_helper.exe, which reads the link and starts the Sogou component it names.
Metrics
infrastructure
7
Zip
Gen traced it pulling three files from a server on Alibaba Cloud in Hong Kong: a legitimate copy of 7-Zip, a malicious DLL, and an encrypted file holding the final payload.
The malicious DLL was saved under the name 7-Zip loads from its own folder at startup, so running 7-Zip loaded the attacker's code instead.
Its only job was to start 7-Zip.
Metrics
infrastructure
443
Domain
SHA-256
29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 malicious DLL loader, written to disk as 7z.dll
SHA-256
749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e encrypted payload file, named p
SHA-256
d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor, internal name core.dll
Domain
mail.uaiubifas[.]top backdoor command s…
Metrics
infrastructure
Android
Affected Product
That research put its user base at more than 455 million people a month across Windows, Android and iOS, and its share of Chinese input-method users at about 70%.
Metrics
infrastructure
Ios
Affected Product
That research put its user base at more than 455 million people a month across Windows, Android and iOS, and its share of Chinese input-method users at about 70%.
Metrics
infrastructure
16.3.0
Software Version
Tencent replied the next day and confirmed on April 21 that a fix was complete and would go out to all users via an automatic update in version 16.3.0.3498.
The fix is in version 16.3.0.3498, which Gen says Tencent pushed to all users by automatic update on April 21, 2026.
Intelligence Sources
The Hacker News
2026-09-11
AlienVault OTX
2026-09-11
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-11T10:50
Comprehensive Tactical Telemetry
Highly Correlated Entities
18x
organisation
Identified Entity
Deploy GRAYRABBIT Backdoor
entity
13x
timeline
Temporal Reference
December 2022
date
4x
target region
Target Country
China
country
4x
industry
Targeted Sector
Government
sector
3x
infrastructure
Affected Product
Windows
software
2x
attribution
Attributing Entity
Google Threat Intelligence
authority
2x
general metric
%
3
%
2x
vulnerability
Exploited CVE
CVE-2021-38003
cve
Contextual Telemetry
Context Block
15 METRICS
source region
Origin Country
China
country
general metric
Research
2,023
research
infrastructure
Zip
7
zip
infrastructure
Domain
443
domain
target region
Target Region
APAC
region
tactic
Cyber Operation Type
Social Engineering
tactic
general metric
People
455,000,000
people
tactic
MITRE ATT&CK Technique
T1059.007 - JavaScript
technique
general metric
Port
443
port
infrastructure
Software Version
16.3.0
version
general metric
Chrome
95
chrome
general metric
Chromium V8 Flaws
41
chromium v8 flaws
general metric
Catalog
32
catalog
general metric
Entities
50
entities
general metric
Chromium
80
chromium
Click on any entity below to view its context in the main text!
Selective Unpublish
Select the networks you want to remove this post from. The system will try to delete the real post through the API and clean the database so you can publish it again.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.