INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

China-Linked UNC3569 Exploits Sogou Input Method Flaw for GRAYRABBIT

| 2026-09-11 07:56 HIGH HIGH EXPLOITED VULNERABILITY MALWARE & BOTNETS STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor called GRAYRABBIT on victims' computers. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns and develops Sogou, fixed the flaw in April 2026. Gen Digital found the flaw while investigating a live intrusion by UNC3569, a group that Google Threat Intelligence ties to China and places in the country's hacker-for-hire scene. The attack affected an estimated 455 million people per month across Windows, Android, and iOS users of Sogou Input Method, with over 70% of those users being from China. The backdoor installed by the attackers gave them a remote command shell, allowed files to be moved in both directions, and could load additional modules from their server at any time.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2021-38003, CVE-2026-51990 and treat internet-facing systems that were not patched in time as potentially compromised until verified. • User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures. • Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

749160••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
d7a3c7••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
29c7ee••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
no•••••.top
ma•••••.top
7z•••••.dll
co•••••.dll
ch•••••.html
bi•••••.exe
8.218.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2021-38003CVE-2021-38003 CVE-2026-51990CVE-2026-51990
Target & Sectors
NORTH_AMERICA NORTH_AMERICA APAC APAC educationeducation technologytechnology governmentgovernment financefinance
Incident Timeline
‎around March 2020
Threat actors exploited a vulnerability in Sogou's custom version of Chromium, built around March 2020, to deploy the GRAYRABBIT backdoor.
organisation Chromium
‎October 2021
Google fixed a vulnerability in Chrome 95, specifically the Sogou input method flaw, which was exploited by China-linked threat actors to deploy the GRAYRABBIT backdoor.
general_metric 95 Chrome
‎November 3, 2021
Threat actors exploited the Sogou input method flaw to deploy the GRAYRABBIT backdoor, which was later added to CISA's catalog of known vulnerabilities.
‎December 2022
Threat actors exploited a Sogou input method flaw to deploy the GRAYRABBIT backdoor, which was later analyzed and publicly disclosed by Singapore firm STAR Labs in December 2022.
target_region Singapore
organisation STAR Labs
‎April 9, 2026
Tencent fixed a vulnerability in Sogou's input method, tracked as CVE-2026-51990, which was exploited by China-linked threat actors to deploy the GRAYRABBIT backdoor.
vulnerability CVE-2026-51990
organisation Tencent Fixed
‎April 2026
Threat actors exploited a vulnerability in Sogou's input method to deploy the GRAYRABBIT backdoor, which was later patched by Tencent.
‎April 21, 2026
Tencent automatically updated all users to version 16.3.0.3498 on April 21, 2026, after discovering and patching the Sogou input method flaw exploited by China-linked threat actors for GRAYRABBIT backdoor deployment.
infrastructure 16.3.0
‎April 21
The vulnerability in Sogou's input method was patched on April 21 with an automatic update, version 16.3.0.3498, which would be distributed to all users by Tencent.
infrastructure 16.3.0
‎2026/09/11
A China-linked hacking group exploited a flaw in Sogou Input Method to install the GRAYRABBIT backdoor on victims' computers.
organisation Deploy GRAYRABBIT Backdoor
infrastructure Windows
infrastructure Android
infrastructure Ios
organisation the University of Toronto
organisation DLL
infrastructure 7 Zip
organisation IP 8.218.50[.]207
organisation Path
organisation TCP
organisation Domain mail.uaiubifas[.]top backdoor command
organisation Domain
infrastructure 443 Domain
organisation Chrome
organisation JSON.stringify
organisation Google
organisation Tencent
organisation The Hacker News
organisation NTFS
organisation qq.com
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
7
Zip
Metrics
infrastructure
443
Domain
Metrics
infrastructure
‎Android
Affected Product
Metrics
infrastructure
‎Ios
Affected Product
Metrics
infrastructure
‎16.3.0
Software Version