The record
Written from the 1 report below. Nothing here is unsourced.
- A China-linked hacking group tracked as UNC3569 exploited a flaw in Sogou Input Method to install a backdoor called GRAYRABBIT on victims' Windows computers, security company Gen Digital reported.
- Tencent, which owns Sogou, fixed the flaw in April 2026, but the patched version still ships a 2020 browser engine with its sandbox switched off.
- The attack began with a crafted sgbiz: link that a single click could turn into code running with the user's full privileges.
- Sogou Input Method is used by more than 455 million people a month, so any flaw in it puts a very large population at risk.
- Google Threat Intelligence ties UNC3569 to China's hacker-for-hire scene and says the group has targeted government, education, technology, and finance sectors mostly in East and Southeast Asia.
What to watch next
- Whether Tencent updates the outdated Chromium engine and re-enables the browser's sandbox in Sogou Input Method.
- Whether the still-unpatched 2020-era browser bugs in Sogou's Chromium build can be reached and exploited the same way.
- How attackers deliver such links in practice, since neither company has confirmed what confirmation prompts victims saw.
Coverage1
1 report
English national1
All filed from India
Named China · Singapore · United States · Alibaba Cloud · Sogou · Sogou Input Method · Citizen Lab · Gen Digital · Google Threat Intelligence · GRAYRABBIT · STAR Labs · Tencent · UNC3569
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
