Sogou Input Method Exploited in Espionage Campaign
A seemingly innocuous link transformed a popular Chinese character input application into a vulnerable gateway for espionage. The security firm Gen exposed a sophisticated exploit chain utilized by the UNC3569 threat group to infect users of the Sogou Input Method for Windows with the formidable GRAYRABBIT backdoor. Boasting hundreds of millions of installations, this software became a prime target; according to Gen experts, merely clicking a meticulously crafted link was sufficient to initiate the devastating attack.
The Mechanics of CVE-2026-51990
This critical vulnerability has been officially designated as CVE-2026-51990. Currently, authorities have not yet published a formal CVSS score or severity rating for this flaw. The attack sequence commences with the proprietary sgbiz: protocol. While its handler verified the executing module, it fatally failed to sanitize the transmitted parameters. Exploiting this oversight, the assailant launched the SGMyInput.exe theme store component, subsequently coercing the embedded browser to navigate toward an arbitrary, malicious destination.
Deep within the Sogou architecture operated CEF 80, built upon an antiquated Chromium 80.0.3987.163 framework dating back to 2020. The developers had inexplicably disabled the security sandbox and crucial web defenses, thereby allowing the malicious webpage to exploit long-documented V8 engine flaws with virtually zero resistance. In their practical assaults, UNC3569 weaponized CVE-2021-38003 – a vulnerability boasting a severe 8.8 CVSS 3.1 score – which afflicts Chrome iterations prior to version 95.0.4638.69.
Deploying the GRAYRABBIT Backdoor
The exploit flawlessly executed a diminutive loader, which then retrieved a legitimate 7-Zip executable, a weaponized DLL, and the encrypted GRAYRABBIT payload directly from a compromised Alibaba Cloud server. Subsequently, the malicious library was stealthily activated via a classic DLL hijacking technique executed alongside the 7z.exe file. The loader also intelligently audited the active process count to deliberately hinder sandbox analysis, ultimately decrypting the payload and executing it directly within the system memory.
GRAYRABBIT provides its operator with a robust remote command shell, granting the capability to launch processes, transfer clandestine files, harvest sensitive system intelligence, and download auxiliary modules. The malicious code operated strictly under the privileges of the active user; thus, it did not automatically orchestrate an escalation to administrator rights. Google threat intelligence previously linked the UNC3569 syndicate to highly targeted campaigns against government agencies, educational institutions, and prominent technology and financial organizations.
Patching and Dispute Over Exploitation
Gen responsibly disclosed this critical flaw to Tencent on April 9. By April 21, the company swiftly deployed a comprehensive patch via an automated update, elevating the Sogou Input Method to version 16.3.0.3498. The fortified handler now exclusively accepts HTTPS addresses originating from whitelisted domains; however, the antiquated Chromium 80 engine remains tragically unpatched and continues to function without essential sandbox isolation. In their detailed research uncovering this one-click backdoor in Sogou, Gen strongly advises all users to immediately install the absolute latest software version.
A notable discrepancy persists between the two parties regarding the precise execution conditions. Gen firmly asserts that following the initial link click, absolutely no further user interaction was necessary. Conversely, Tencent assessed the overall risk as limited, maintaining that the user would invariably need to manually authorize a subsequent browser popup request.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.