Critical Sogou Input Method Flaw Lets Hackers Deploy GrayRabbit Backdoor via Single Link
A critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows is being actively exploited by threat actor UNC3569 to deploy the GRAYRABBIT backdoor. Attackers send victims a crafted sgbiz: URI link that chains an unvalidated parameter, an outdated sandboxless Chromium 80 instance, and a separate V8 exploit (CVE-2021-38003) to achieve remote code execution with a single click. Once executed, a downloader drops legitimate 7z.exe alongside a malicious DLL and encrypted payload into C:\Users\Public\Documents\, ultimately loading GRAYRABBIT into memory via DLL sideloading. The backdoor communicates with a command-and-control server over raw RC4-encrypted TCP on port 443, supporting shell access, file transfer, and in-memory plugin loading. Tencent has released a patch in version 16.3.0.3498, and users are urged to update immediately and audit process chains and network traffic for signs of compromise.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in