News

UNC3569 uses Sogou Input Method flaw for GrayRabbit

Gen Threat Labs documents CVE-2026-51990, a one-click RCE in Tencent's Sogou Input Method for Windows used by UNC3569 to drop GrayRabbit. Tencent shipped build 16.3.0.3498 on 21 April 2026, 12 days after the 9 April report.

UNC3569 uses Sogou Input Method flaw for GrayRabbit

Gen Threat Labs (Alexandru-Cristian Bardas, 10 September 2026) documented a live UNC3569 intrusion that started inside Tencent's Sogou Input Method for Windows. The write-up reports the chain as CVE-2026-51990 and says the group used it to drop the GrayRabbit backdoor.

This is vendor research from Gen Digital, plus a later MITRE CVE assignment. It is not a CISA Known Exploited Vulnerabilities listing and not a Tencent press release.

Sogou is a Chinese input method editor with hundreds of millions of Windows installs. Gen says the critical one-click remote code execution chains three failures: unvalidated command-line argument injection in the sgbiz: protocol handler (biz_helper.exe), unrestricted URL navigation in the SGMyInput.exe skincenter CEF webview, and an outdated unsandboxed Chromium 80 engine (CEF 80.1.16, Chromium 80.0.3987.163, about March 2020).

UNC3569 is a PRC-nexus group tracked by Google Threat Intelligence. It spans cybercrime and contractor-for-hire work against government, education, technology, and finance, especially in East and Southeast Asia.

The exploit page used CVE-2021-38003, a V8 type confusion bug, against that Chromium 80 build. A 921-byte x64 downloader then pulled a legitimate 7z.exe plus a trojanized 7z.dll and wrote them under C:\Users\Public\Documents. The implant is an x64 maturation of GrayRabbit, exporting CoreClientInstall and CoreClientStart.

C2 was mail.uaiubifas[.]top on TCP 443 as raw TCP, not TLS, with RC4 and the static six-byte key m5b1u3 in 0x1000-byte frames. Staging sat at 8.218.50[.]207 on Alibaba Cloud in Hong Kong. The exploit host was noht1ng[.]top.

Gen reported the bug to Tencent on 9 April 2026. Tencent acknowledged it on 10 April and confirmed a fix, pushed as an automatic update, on 21 April 2026 as Sogou Input Method 16.3.0.3498, a 12-day turnaround.

A CVE request went in on 4 May. MITRE assigned CVE-2026-51990 on 10 July 2026. The patch validates -url and -firsturl to HTTPS and allowlisted host suffixes (sogou.com, qq.com, woa.com, sogou).

Tencent called the chain "relatively complex" and said exploitation can involve inducing the user to authorize a browser pop-up. Gen frames the path it observed as one click on a crafted sgbiz: link. The April build blocks that protocol-handler route. Gen still says the embedded browser keeps no_sandbox=1 and disable-web-security, so the CEF engine remains sandboxless and old.

This is a different product and a different CVE from Cyberpresso's GitLab commits API file-read patch. Related click-and-lure tape includes Microsoft's passkey lures into Microsoft 365 cloud theft.

If you run Sogou Input Method on Windows, confirm the build is 16.3.0.3498 or later, hunt for 7z.exe under Public\Documents loading a sideloaded 7z.dll, and treat mail.uaiubifas[.]top and 8.218.50[.]207 as IOC lookups, not as proof every install was hit.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free