UNC3569 Sogou Input Method exploitation campaign
Campaign
Summary
Hide ▲
Show ▼
The UNC3569 campaign abused a crafted sgbiz: link to exploit Sogou Input Method on Windows, giving the operator code execution and a foothold for the GRAYRABBIT backdoor. The chain let the attacker act with the logged-in user's privileges, turning a link click into remote access. Gen Digital linked the activity to a live intrusion and said UNC3569 has targeted government, education, technology, and finance sectors in East and Southeast Asia since 2021. Tencent fixed the flaw in April 2026 and pushed version 16.3.0.3498 to close the link-handler path.
Cases
Related Happenings
Sogou Input Method Windows link-handler code-execution flaw (CVE-2026-51990)
Vulnerability
H score89
First: 11.09.2026 10:14
Last: 11.09.2026 10:14
Sources 1
How related:
Gen reported the flaw to Tencent on April 9, 2026, and it is tracked as CVE-2026-51990. Tencent replied the next day and confirmed on April 21 that a fix was complete and would go out to all users via an automatic update in version 16.3.0.3498.
About this happening:
Sogou Input Method on Windows had a link-handler flaw in the `sgbiz:` path that let attacker-controlled arguments and browser navigation reach code execution under the...
Sogou Input Method Windows link-handler code-execution flaw (CVE-2026-51990)
VulnerabilityHow related: Gen reported the flaw to Tencent on April 9, 2026, and it is tracked as CVE-2026-51990. Tencent replied the next day and confirmed on April 21 that a fix was complete and would go out to all users via an automatic update in version 16.3.0.3498.
About this happening: Sogou Input Method on Windows had a link-handler flaw in the `sgbiz:` path that let attacker-controlled arguments and browser navigation reach code execution under the...
GRAYRABBIT backdoor deployment via Sogou Input Method exploit
Malware Activity
H score89
First: 11.09.2026 10:14
Last: 11.09.2026 10:14
Sources 1
How related:
The backdoor it installed is GRAYRABBIT, a small program the group has used for years and that Google describes as its first step onto a machine. It gives an attacker a remote command shell, allows files to be moved in both directions, and can load additional modules from the attacker's server at any time.
About this happening:
The GRAYRABBIT backdoor was deployed in a live intrusion against Sogou Input Method users, giving attackers a remote command shell and the ability to stage additional...
GRAYRABBIT backdoor deployment via Sogou Input Method exploit
Malware ActivityHow related: The backdoor it installed is GRAYRABBIT, a small program the group has used for years and that Google describes as its first step onto a machine. It gives an attacker a remote command shell, allows files to be moved in both directions, and can load additional modules from the attacker's server at any time.
About this happening: The GRAYRABBIT backdoor was deployed in a live intrusion against Sogou Input Method users, giving attackers a remote command shell and the ability to stage additional...
Atlassian Rovo Chat rovoChatPrompt prompt-injection security flaw
Vulnerability
H score1
First: 08.08.2026 11:54
Last: 08.08.2026 11:54
Sources 1
About this happening:
The Atlassian Rovo Chat rovoChatPrompt vulnerability let attacker-supplied instructions preload into the assistant and exfiltrate Jira, Confluence, and connected-a...
Atlassian Rovo Chat rovoChatPrompt prompt-injection security flaw
VulnerabilityAbout this happening: The Atlassian Rovo Chat rovoChatPrompt vulnerability let attacker-supplied instructions preload into the assistant and exfiltrate Jira, Confluence, and connected-a...
ClickLock ClickFix macOS targeting campaign
Campaign
H score33
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...
ClickLock ClickFix macOS targeting campaign
CampaignAbout this happening: Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...
UniFi OS Server unauthenticated root RCE chain (multiple vulnerabilities)
Vulnerability
H score25
First: 08.06.2026 18:51
Last: 08.06.2026 18:51
Sources 1
About this happening:
UniFi OS Server is exposed to an unauthenticated root RCE chain that combines CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, putting versions 5.0.6 and...
UniFi OS Server unauthenticated root RCE chain (multiple vulnerabilities)
VulnerabilityAbout this happening: UniFi OS Server is exposed to an unauthenticated root RCE chain that combines CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, putting versions 5.0.6 and...
Latest development: 24.06.2026 15:32
CISA added CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 to the Known Exploited Vulnerabilities (KEV) catalog after warnings that threat actors were targeting UniFi OS Server devices and multiple users reported in-the-wild exploitation that created rogue administrator accounts named 'John Sim' on affected Ubiquiti systems.
Timeline
-
11.09.2026 10:14 1 articles · 2h ago
Gen Digital notifies Tencent of Sogou Input Method flaw
Initial DisclosureGen Digital reported a flaw in Sogou Input Method to Tencent on April 9, 2026, and the issue is tracked as CVE-2026-51990.
Show sources
- China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor — thehackernews.com — 11.09.2026 10:14
-
11.09.2026 10:14 1 articles · 2h ago
Tencent ships fix for Sogou Input Method link-handler flaw
Mitigation Patch UpdateTencent confirmed on April 21, 2026 that a fix was complete and would reach all users through an automatic update in version 16.3.0.3498.
Show sources
- China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor — thehackernews.com — 11.09.2026 10:14
-
11.09.2026 03:00 2 articles · 9h ago
UNC3569 uses crafted sgbiz: link to deploy GRAYRABBIT
Technical Analysis UpdateGen Digital published research on September 11, 2026 describing a China-linked UNC3569 intrusion that used a crafted sgbiz: link against Sogou Input Method on Windows to install the GRAYRABBIT backdoor and execute code with the logged-in user's privileges.
Show sources
- China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor — thehackernews.com — 11.09.2026 10:14
- China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor — thehackernews.com — 11.09.2026 10:14