The Maivia Gazette

Verified AI news, every morning

Security

China-aligned group exploits one-click flaw in Tencent's Sogou keyboard to plant GrayRabbit backdoor

Gen Threat Labs says UNC3569 chains a URI argument injection, an unrestricted webview, and an unsandboxed Chromium engine in software with hundreds of millions of installs.

A grey rabbit-shaped shadow slips out from under a pried-up keycap on a dark keyboard.
AI-generated illustration, not event photography.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.

Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor, according to researchers at Gen Digital. The flaw, tracked as CVE-2026-51990, is a one-click remote code execution issue. Gen Threat Labs says it observed the UNC3569 group exploiting it in the wild through a crafted link. Sogou Input Method lets users type Chinese characters on a standard keyboard and reportedly has hundreds of millions of installations in China. It also ships a custom link handler and a built-in browser based on an outdated Chromium engine. The attackers chain three weaknesses: an unvalidated command-line argument injection in the application's sgbiz: URI, unrestricted URL navigation in a CEF-based webview, and the outdated, unsandboxed Chromium engine. The attack begins when a victim clicks a crafted sgbiz: link. Windows invokes Sogou's protocol handler, biz_helper.exe, which passes attacker-controlled arguments to the legitimate SGMyInput.exe executable without validation, letting the attacker steer the embedded browser and ultimately run code. Because the input method runs on so many consumer and corporate machines, the flaw gives an espionage group a broad foothold that requires only a single click. Users should update Sogou Input Method as soon as Tencent's fix is available and treat unexpected sgbiz: links as hostile.

Sources

  1. BleepingComputerHackers exploit Tencent app flaw to deploy GrayRabbit malwarePublished · fetched

Also in this edition