-
UNC3569 exploited CVE-2026-51990 in Sogou Input Method to gain code execution through a specially crafted sgbiz: link.
-
The attack abused Sogou’s old Chromium 80 browser, which ran without its sandbox and with key web security controls disabled.
-
Tencent patched the flaw in April, but Gen says the outdated embedded browser still needs further hardening.
China-linked hackers used a critical flaw in Tencent’s Sogou Input Method for Windows to deliver the GRAYRABBIT backdoor.
Gen Threat Labs found the flaw CVE-2026-51990 while investigating a real intrusion linked to UNC3569, a China-linked threat actor group. UNC3569 has a history of targeting government, education, technology and financial organizations in espionage campaigns.
Gen alerted Tencent on April 9. And 12 days later, Tencent released a fix. They pushed the patched version, 16.3.0.3498, through Sogou’s automatic update system. MITRE later assigned the CVE on July 10.
Gen says the attack could start with a single specially crafted sgbiz: link. The link abused a custom protocol used by Sogou to launch its own components.
Tencent offered a more cautious view. The organization stated that the attack vector was relatively complicated, involving social engineering tactics for the authorization of the prompt. In any case, the attack demonstrates how reliable desktop software can unexpectedly become an attack vector.
Sogou’s Built-in Browser Created the Opening
Sogou Input Method uses the Windows sgbiz: protocol to connect different parts of the application. Gen found that the protocol handler checked which Sogou program it should launch. But it did not properly check the arguments passed to that program.
Attackers could use those arguments to launch Sogou’s SGMyInput.exe with instructions to open its skin marketplace. That page normally loads a browser window. The problem was that attackers could also supply the web address that the embedded browser should open.
The browser then accepted an attacker-controlled URL without checking its destination. That created the first major weakness in the chain.
The second one was even more serious. Sogou had distributed a browser with the old Chromium 80 engine, released around March 2020. Gen found that the browser still used this old engine in the version it examined.
The browser also ran with its sandbox disabled. Its same-origin protection was disabled too. Another setting allowed local file access from files. Those protections normally help limit what malicious web content can do. Without them, a successful browser exploit could reach the Windows system with the privileges of the logged-in user.
UNC3569 Used an Old Chrome Flaw
UNC3569 also exploited an older Chrome flaw CVE-2021-38003. This flaw affects Google’s V8 JavaScript engine. It can be triggered by malicious web content. This helped them to gain access to the outdated browser in Sogou. If successful, it can corrupt memory.
CISA added this vulnerability to its KEV catalog in November 2021. That made the old Chromium version inside Sogou a useful target.
Gen said the exploit page delivered JavaScript designed to abuse the V8 flaw. The resulting exploit gave the attackers code execution inside the Sogou process. The attackers then used shellcode to download the next stage of the malware.
GRAYRABBIT Gave Attackers Remote Access
The intrusion did not stop at code execution. Gen found that the exploit downloaded several files from an Alibaba Cloud server in Hong Kong. One was a legitimate 7-Zip executable. Another was a malicious DLL. A third file contained an encrypted payload. The hackers employed a sideloading technique to make the 7-Zip application load the malicious DLL.
That loader eventually unpacked GRAYRABBIT, a backdoor that UNC3569 has used in earlier campaigns. Google researchers have previously documented the malware as one of the group’s tools.
GRAYRABBIT can give attackers a remote command shell and let them run programs on the infected machine. It can also move files, collect system information, and load additional modules.
Gen identified a command-and-control domain used by the sample as mail.uaiubifas[.]top over port 443. The malware used raw TCP traffic with RC4 encryption rather than normal TLS.
The Patch Closed One Door, not the Whole Problem
Tencent moved quickly after Gen reported the vulnerability. The April update blocked the attack path by adding checks around attacker-controlled URLs. It also limited navigation to approved domains.
However, Gen found that the embedded browser itself remained largely unchanged. The patched software still used the old Chromium-based component. The sandbox remained disabled, and key browser security settings were still turned off.
That does not mean the same exploit still works. The specific route through the sgbiz: handler was blocked. But it does highlight a wider security problem.
Desktop applications increasingly include full browser engines for features that users may barely notice. If those engines become outdated, they can create a large attack surface inside otherwise trusted software. Sogou’s case shows how that risk can turn an ordinary input tool into a foothold for cyber espionage.
The same risk can affect other trusted software ecosystems too. Hackers recently planted backdoors in more than 30 WordPress plugins, forcing developers to issue emergency security updates. The incident shows how attackers can abuse software that organizations and users already trust to gain access to larger numbers of systems.
Organizations using Sogou Input Method on Windows should verify that systems have version 16.3.0.3498 or later and review endpoint and network logs for signs of GRAYRABBIT activity. Gen has also published hashes and network indicators that defenders can use for threat hunting.