Find notable cyber news and cases, enriched with sources, timelines, and signals.

GRAYRABBIT backdoor deployment via Sogou Input Method exploit

Malware Activity
First reported
Last updated
Happening score
H score 89
1 unique sources, 1 articles

Summary

Hide ▲

The GRAYRABBIT backdoor was deployed in a live intrusion against Sogou Input Method users, giving attackers a remote command shell and the ability to stage additional modules. The payload turned a Windows exploit chain into persistent attacker access on victim machines. The backdoor traffic was tied to mail.uaiubifas[.]top on port 443, raising monitoring value for defenders.

Related Happenings

UNC3569 Sogou Input Method exploitation campaign

Campaign
H score89 First: 11.09.2026 10:14 Last: 11.09.2026 10:14 Sources 1

How related: Gen found the flaw while investigating a live intrusion by UNC3569, a group that Google Threat Intelligence ties to China and places in the country's hacker-for-hire scene.

About this happening: The UNC3569 campaign abused a crafted sgbiz: link to exploit Sogou Input Method on Windows, giving the operator code execution and a foothold for the GRAYRABBIT ba...

Silver Fox South Asia phishing campaign

Campaign
H score34 First: 24.03.2026 18:00 Last: 24.03.2026 18:00 Sources 1

About this happening: The Silver Fox campaign now includes BYOVD abuse of a previously unknown WatchDog Anti-malware driver, amsdk.sys (version 1.0.600), to disable security tools on co...

Timeline

  1. 11.09.2026 10:14 1 articles · 2h ago

    Gen Digital reports Sogou Input Method flaw to Tencent

    Initial Disclosure

    Gen Digital reported a flaw in Sogou Input Method to Tencent and the issue was tracked as CVE-2026-51990. The disclosure covered a Windows link-handler weakness that let a crafted sgbiz: link pass attacker-chosen arguments into Sogou components.

    Show sources
  2. 11.09.2026 10:14 1 articles · 2h ago

    Tencent completes fix for the Sogou Input Method link-handler flaw

    Mitigation Patch Update

    Tencent confirmed a fix for CVE-2026-51990 and pushed version 16.3.0.3498 to all users through automatic update. Gen said the patch blocks attacker-controlled web addresses in biz_helper.exe by rejecting non-HTTPS inputs and checking hostnames against allowed endings.

    Show sources
  3. 11.09.2026 10:14 2 articles · 2h ago

    Gen Digital details UNC3569's GRAYRABBIT intrusion chain

    Technical Analysis Update

    Gen Digital published research describing a live intrusion by UNC3569 that used a crafted sgbiz: link against Sogou Input Method on Windows to install the GRAYRABBIT backdoor. The chain reached a malicious page carrying CVE-2021-38003, then staged a downloader that pulled a legitimate 7-Zip binary, a malicious DLL, and an encrypted payload from 8.218.50[.]207 before deploying GRAYRABBIT with remote shell and file-transfer capability.

    Show sources