GRAYRABBIT backdoor deployment via Sogou Input Method exploit
Malware Activity
Summary
Hide ▲
Show ▼
The GRAYRABBIT backdoor was deployed in a live intrusion against Sogou Input Method users, giving attackers a remote command shell and the ability to stage additional modules. The payload turned a Windows exploit chain into persistent attacker access on victim machines. The backdoor traffic was tied to mail.uaiubifas[.]top on port 443, raising monitoring value for defenders.
Related Happenings
UNC3569 Sogou Input Method exploitation campaign
Campaign
H score89
First: 11.09.2026 10:14
Last: 11.09.2026 10:14
Sources 1
How related:
Gen found the flaw while investigating a live intrusion by UNC3569, a group that Google Threat Intelligence ties to China and places in the country's hacker-for-hire scene.
About this happening:
The UNC3569 campaign abused a crafted sgbiz: link to exploit Sogou Input Method on Windows, giving the operator code execution and a foothold for the GRAYRABBIT ba...
UNC3569 Sogou Input Method exploitation campaign
CampaignHow related: Gen found the flaw while investigating a live intrusion by UNC3569, a group that Google Threat Intelligence ties to China and places in the country's hacker-for-hire scene.
About this happening: The UNC3569 campaign abused a crafted sgbiz: link to exploit Sogou Input Method on Windows, giving the operator code execution and a foothold for the GRAYRABBIT ba...
Silver Fox South Asia phishing campaign
Campaign
H score34
First: 24.03.2026 18:00
Last: 24.03.2026 18:00
Sources 1
About this happening:
The Silver Fox campaign now includes BYOVD abuse of a previously unknown WatchDog Anti-malware driver, amsdk.sys (version 1.0.600), to disable security tools on co...
Silver Fox South Asia phishing campaign
CampaignAbout this happening: The Silver Fox campaign now includes BYOVD abuse of a previously unknown WatchDog Anti-malware driver, amsdk.sys (version 1.0.600), to disable security tools on co...
Timeline
-
11.09.2026 10:14 1 articles · 2h ago
Gen Digital reports Sogou Input Method flaw to Tencent
Initial DisclosureGen Digital reported a flaw in Sogou Input Method to Tencent and the issue was tracked as CVE-2026-51990. The disclosure covered a Windows link-handler weakness that let a crafted sgbiz: link pass attacker-chosen arguments into Sogou components.
Show sources
- China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor — thehackernews.com — 11.09.2026 10:14
-
11.09.2026 10:14 1 articles · 2h ago
Tencent completes fix for the Sogou Input Method link-handler flaw
Mitigation Patch UpdateTencent confirmed a fix for CVE-2026-51990 and pushed version 16.3.0.3498 to all users through automatic update. Gen said the patch blocks attacker-controlled web addresses in biz_helper.exe by rejecting non-HTTPS inputs and checking hostnames against allowed endings.
Show sources
- China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor — thehackernews.com — 11.09.2026 10:14
-
11.09.2026 10:14 2 articles · 2h ago
Gen Digital details UNC3569's GRAYRABBIT intrusion chain
Technical Analysis UpdateGen Digital published research describing a live intrusion by UNC3569 that used a crafted sgbiz: link against Sogou Input Method on Windows to install the GRAYRABBIT backdoor. The chain reached a malicious page carrying CVE-2021-38003, then staged a downloader that pulled a legitimate 7-Zip binary, a malicious DLL, and an encrypted payload from 8.218.50[.]207 before deploying GRAYRABBIT with remote shell and file-transfer capability.
Show sources
- China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor — thehackernews.com — 11.09.2026 10:14
- China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor — thehackernews.com — 11.09.2026 10:14