UNC3569 Exploitation and Remediation of Sogou Input Method on Windows
Case score 89
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 89
- Main story score
- 89
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 1
- Vulnerability Primary record for CVE-2026-51990, the vulnerable Windows link-handler path, and the vendor fix. main
- Campaign Direct exploitation context tying UNC3569 and GRAYRABBIT delivery to the same Sogou Input Method flaw. context
Overview
Latest development Open development history UNC3569 uses crafted sgbiz: link to deploy GRAYRABBIT Gen Digital published research on September 11, 2026 describing a China-linked UNC3569 intrusion that used a crafted sgbiz: link against Sogou Input Method on Windows to install the GRAYRABBIT backdoor and execute code with the logged-in user's privileges.
-
Tencent completes Sogou Input Method fix and automatic update
Tencent confirmed on April 21, 2026 that a fix for Sogou Input Method version 16.3.0.3498 was complete and would reach users through automatic update.
-
Gen Digital reports Sogou Input Method flaw to Tencent
Gen Digital reported the Sogou Input Method Windows flaw to Tencent on April 9, 2026 after investigating a live intrusion tied to UNC3569; the issue is tracked as CVE-2026-51990.
-
Gen Digital details UNC3569 Sogou Input Method exploitation and GRAYRABBIT delivery
Gen Digital published research on September 11, 2026 describing a UNC3569 campaign that used a crafted sgbiz: link against Sogou Input Method on Windows to install GRAYRABBIT and execute code with the logged-in user's privileges; the attack page also carried an exploit for CVE-2021-38003.