China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

A China-linked hacking group known as UNC3569 exploited a vulnerability in the Sogou Input Method to deploy the GRAYRABBIT backdoor. While Tencent has issued a patch, security researchers note that the underlying architectural flaws in the software remain unaddressed.
Why it matters
Sogou is used by over 455 million people, making this a significant supply-chain security risk for users of Chinese-language input software globally.
A China-linked hacking group exploited a flaw in Sogou Input Method , one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday .
The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns and develops Sogou, fixed the flaw in April 2026.
Gen found the flaw while investigating a live intrusion by UNC3569 , a group that Google Threat Intelligence ties to China and places in the country's hacker-for-hire scene. Google has tracked the group since 2021 and says it has targeted government, education, technology, and finance sectors, mostly in East and Southeast Asia.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in