China-Linked UNC3569 Leverages Sogou Input Method Flaw to Deploy GrayRabbit Backdoor
Security researchers have confirmed that a group identified as UNC3569, widely believed to operate out of China, has weaponized a critical remote‑code‑execution flaw in Tencent's Sogou Input Method for Windows to install the GRAYRABBIT backdoor on compromised machines.
The vulnerability, catalogued as CVE‑2026‑51990, is triggered by a single user interaction—often a click on a seemingly benign dialog—allowing an attacker to execute arbitrary code with the privileges of the logged‑in user. Because Sogou Input Method is pre‑installed on many Chinese‑language Windows systems, the exploit can reach a large and diverse user base with minimal effort.
UNC3569 has appeared in previous threat‑intel reports linked to espionage‑oriented campaigns targeting government and corporate networks in East Asia. Their modus operandi typically involves leveraging zero‑day or near‑zero‑day flaws in widely deployed software, followed by the rapid deployment of custom backdoors that enable long‑term persistence and data exfiltration.
The GRAYRABBIT payload delivered in this instance is a modular backdoor capable of executing commands, downloading additional modules, and establishing encrypted communication channels with command‑and‑control servers. Analysts note that its architecture resembles other espionage tools used by state‑aligned actors, suggesting a focus on stealth and adaptability.
Experts warn that the compromise of an input‑method editor (IME) presents a particularly insidious risk. An IME runs at a high privilege level and processes every keystroke, meaning a malicious component could capture credentials, inject malicious text, or manipulate user actions without detection.
Tencent has issued an emergency patch that addresses the CVE‑2026‑51990 flaw and recommends that users apply the update immediately. Security vendors are also publishing detection signatures for the GRAYRABBIT backdoor, and organizations are advised to audit systems for unexpected Sogou Input Method binaries and monitor network traffic for the backdoor’s characteristic beaconing patterns.
The incident underscores the broader challenge of securing software that is deeply integrated into everyday workflows. As threat actors continue to target popular utilities for initial access, analysts expect heightened scrutiny of supply‑chain risks and a push for faster patch cycles across the industry.
Comments (0)
Be the first to comment.
Join the discussion