Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Campaign

UNC3569 Exploitation and Remediation of Sogou Input Method on Windows

Updated 11.09.2026 10:14
Case score 89
Members 2 First seen 11.09.2026 10:14 Latest activity 11.09.2026 10:14

Overview

**Sogou Input Method on Windows** was exploited through a crafted **sgbiz:** link that reached **CVE-2026-51990**, giving attackers code execution with the logged-in user's privileges and leading to **GRAYRABBIT** installation. The same intrusion chain also used **CVE-2021-38003** in the product's Chromium-based browser path, and available material ties the operation to **UNC3569**. The flaw was reported to **Tencent** in April 2026, and the vendor said a fix was completed in **version 16.3.0.3498** and pushed through automatic update. Public details still leave open the full affected-version range and whether broader browser-engine weaknesses inside the product create additional exposure beyond the closed link-handler path.
Latest development Open development history 3 earlier developments UNC3569 uses crafted sgbiz: link to deploy GRAYRABBIT Gen Digital published research on September 11, 2026 describing a China-linked UNC3569 intrusion that used a crafted sgbiz: link against Sogou Input Method on Windows to install the GRAYRABBIT backdoor and execute code with the logged-in user's privileges.
  1. Earlier development

    Tencent completes Sogou Input Method fix and automatic update

    Tencent confirmed on April 21, 2026 that a fix for Sogou Input Method version 16.3.0.3498 was complete and would reach users through automatic update.

  2. Earlier development

    Gen Digital reports Sogou Input Method flaw to Tencent

    Gen Digital reported the Sogou Input Method Windows flaw to Tencent on April 9, 2026 after investigating a live intrusion tied to UNC3569; the issue is tracked as CVE-2026-51990.

  3. Earlier development

    Gen Digital details UNC3569 Sogou Input Method exploitation and GRAYRABBIT delivery

    Gen Digital published research on September 11, 2026 describing a UNC3569 campaign that used a crafted sgbiz: link against Sogou Input Method on Windows to install GRAYRABBIT and execute code with the logged-in user's privileges; the attack page also carried an exploit for CVE-2021-38003.

Signals

Impact signals
Exploitation
CVEs/products
Geographic context
Remediation
Status
Threat context

Threat actor context

1 listed

Malware context

1 families

Technical intelligence

Existing Case data

Member happenings

Vulnerability Sogou Input Method Windows link-handler code-execution flaw (CVE-2026-51990)
Updated 11.09.2026 10:14 Lead Contribution 89
Exploitation Active Exploitation Patch Patch Available

**Sogou Input Method on Windows** had a **link-handler flaw** in the `sgbiz:` path that let attacker-controlled arguments and browser navigation reach **code execution** under the logged-in user's privileges. **Gen Digital** tied the bug to **CVE-2026-51990** and said **Tencent** completed a fix for **version 16.3.0.3498** in **April 2026**. The flaw was used in a **live intrusion** to deliver the **GRAYRABBIT** backdoor. The patch closed the link-handler entry point, but the broader browser-engine weaknesses in the product were not removed.

Campaign UNC3569 Sogou Input Method exploitation campaign
Updated 11.09.2026 10:14 Context
Campaign Active Patch Patch Available

The **UNC3569** campaign abused a **crafted sgbiz: link** to exploit **Sogou Input Method on Windows**, giving the operator code execution and a foothold for the **GRAYRABBIT** backdoor. The chain let the attacker act with the logged-in user's privileges, turning a link click into remote access. Gen Digital linked the activity to a **live intrusion** and said **UNC3569** has targeted **government, education, technology, and finance** sectors in **East and Southeast Asia** since **2021**. Tencent fixed the flaw in **April 2026** and pushed **version 16.3.0.3498** to close the link-handler path.