China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
- ID
- 23462
- Status
- summarized
- Published
- 11 Sep 2026, 3:14 PM
- Fetched
- 11 Sep 2026, 4:09 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 11 Sep 2026, 4:10 PM
- Tags
- Audience
- developersai_agent_userssaas_founders
What happened
A China-linked hacker-for-hire group UNC3569 exploited a flaw in Sogou Input Method (455M+ monthly users, ~70% of Chinese input method market) to deploy the GRAYRABBIT backdoor via crafted sgbiz: links on Windows. Tencent patched the specific entry point in April 2026, but the underlying built-in browser engine remains a 2020 version with its sandbox still disabled. The group has targeted government, education, technology, and finance sectors mostly in East and Southeast Asia since at least 2021.
Why it matters
If your team or users in Southeast Asia install Sogou Input Method on Windows machines, the patched version still ships with an unsandboxed 2020 browser engine — the attack surface that made this possible is not fully closed. Organisations in the targeted sectors (government, education, tech, finance) in the region should treat Sogou on Windows as a persistent risk and consider whether it belongs on managed devices at all.
Discussion angle
The incomplete patch is the real story: Tencent blocked the specific entry point but left the architectural weakness (unsandboxed 2020 browser engine) intact — what does this tell us about trusting vendor patches in widely-deployed software, especially for teams operating in the targeted Southeast Asian region?