AI Weekly Malaysia

Back to items Summaries

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

ID
23462
Status
summarized
Published
11 Sep 2026, 3:14 PM
Fetched
11 Sep 2026, 4:09 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.5
Created
11 Sep 2026, 4:10 PM
Tags
Audience
developersai_agent_userssaas_founders

What happened

A China-linked hacker-for-hire group UNC3569 exploited a flaw in Sogou Input Method (455M+ monthly users, ~70% of Chinese input method market) to deploy the GRAYRABBIT backdoor via crafted sgbiz: links on Windows. Tencent patched the specific entry point in April 2026, but the underlying built-in browser engine remains a 2020 version with its sandbox still disabled. The group has targeted government, education, technology, and finance sectors mostly in East and Southeast Asia since at least 2021.

Why it matters

If your team or users in Southeast Asia install Sogou Input Method on Windows machines, the patched version still ships with an unsandboxed 2020 browser engine — the attack surface that made this possible is not fully closed. Organisations in the targeted sectors (government, education, tech, finance) in the region should treat Sogou on Windows as a persistent risk and consider whether it belongs on managed devices at all.

Discussion angle

The incomplete patch is the real story: Tencent blocked the specific entry point but left the architectural weakness (unsandboxed 2020 browser engine) intact — what does this tell us about trusting vendor patches in widely-deployed software, especially for teams operating in the targeted Southeast Asian region?

Top