China‑linked UNC3569 exploits Sogou Input Method flaw to drop GRAYRABBIT backdoor
A hacking group tied to China, identified in security circles as UNC3569, leveraged a vulnerability in the widely used Sogou Input Method to install the GRAYRABBIT backdoor on targeted Windows machines, according to research released by Gen Digital on Thursday.
Sogou Input Method, a popular keyboard extension that enables efficient typing of Chinese characters, is installed on millions of personal and corporate computers worldwide. Its deep integration with the operating system makes it an attractive target for threat actors seeking a foothold in environments where the software is trusted.
The researchers at Gen Digital say the attackers exploited a flaw that allowed arbitrary code execution when the input method processed crafted data. By delivering a malicious payload through this pathway, the group was able to bypass typical security controls and gain persistent access to the compromised systems.
Once the vulnerability was abused, the GRAYRABBIT backdoor was dropped onto the host. The malware provides remote command‑and‑control capabilities, enabling operators to execute commands, move laterally within networks, and exfiltrate data. Its modular design allows additional functionalities to be added as needed, increasing the threat’s longevity.
The incident highlights a broader supply‑chain risk, as software that is widely distributed and deeply embedded in daily workflows can become a conduit for espionage or ransomware campaigns. Enterprises that rely on Sogou for Chinese language support may find themselves exposed unless they apply security updates or consider alternative input solutions.
Gen Digital’s advisory urges users to update Sogou Input Method to the latest version, apply all relevant Windows patches, and monitor for indicators of compromise associated with GRAYRABBIT. Security teams are also advised to conduct threat‑hunts focused on unusual input‑method activity and to review outbound traffic for connections to known command‑and‑control hosts. The attribution to a China‑linked group underscores ongoing geopolitical cyber‑espionage trends, and analysts expect further scrutiny of other popular regional software tools.
Comments (0)
Be the first to comment.
Join the discussion