[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ff4BpSbhGNOiZvmgf5s8YwRPDGvwBKIbpBRaJeUArEAM":3},{"article":4,"iocs":53},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":35},"46ae7fdb-374b-4ff6-b92f-a75a22927dca","Hackers exploit Tencent app flaw to deploy GrayRabbit malware","hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware-b2a972","Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]","China-aligned threat actors, identified as UNC3569, are exploiting a critical one-click RCE vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows. This flaw allows them to deploy the GrayRabbit backdoor by chaining together multiple weaknesses in the application's protocol handler, webview, and outdated Chromium engine.","Hackers exploit Tencent app flaw to deploy GrayRabbit malware via UNC3569 group.","Hackers exploit Tencent app flaw to deploy GrayRabbit malware By Bill Toulas September 13, 2026 10:26 AM 0 Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor. Researchers at cybersecurity company Gen Digital warn that the security issue is a one-click remote code execution (RCE) flaw. \"We observed this vulnerability actively exploited in the wild by the UNC3569 threat group to deploy the GRAYRABBIT backdoor through a crafted link,\" Gen Threat Labs says. Sogou Input Method is a popular Windows application that lets users type Chinese characters using a standard keyboard and also offers a custom link handler and a built-in web browser using an outdated Chromium engine. Developed by Chinese tech giant Tencent, Sogou Input Method reportedly has hundreds of millions of installations in China. Gen Threat Labs reports that UNC3569 chains three weaknesses in the product: an unvalidated command-line argument injection in the sgbiz: URI an unrestricted URL navigation in a CEF-based webview an outdated, unsandboxed Chromium browser engine The attack chain starts with the victim clicking a crafted sgbiz: custom URI, causing Windows to invoke Sogou’s biz_helper.exe protocol handler, which passes attacker-controlled command-line arguments to the legitimate SGMyInput.exe executable without validating them. The attacker-injected arguments open Sogou’s skincenter component and instruct its embedded Chromium webview to load an attacker-controlled URL. Sogou does not restrict the URL’s scheme or destination. In the third stage, a malicious page exploits a known vulnerability in Sogou’s outdated Chromium 80 engine. Because the browser runs without a sandbox and with important web-security protections disabled, the exploit achieves code execution and installs the GrayRabbit backdoor. The UNC3569 attack chainSource: Gen Threat Labs In 2024, Google researchers described GrayRabbit as a modular malware family and linked it to UNC3569, a China-based threat actor operating across both the cybercrime and cyber contractor-for-hire ecosystems. The malware sample that Gen Threat Labs analyzed is a more mature 64-bit variant with an expanded command set and RC4-encoded command-and-control (C2) configuration. Its capabilities include process execution, opening interactive reverse shells, uploading and downloading files, collecting system and user information, and reflectively loading plugins in the host’s memory. Gen Threat Labs reported their findings to Tencent on April 9, and the software vendor deployed a fix in Sogou Input Method version 16.3.0.3498, released on April 21. The patch validates the URL arguments accepted through the protocol handler, permits only HTTPS, and restricts navigation to approved domains related to Sogou and Tencent. However, the researchers warned that the underlying browser remains outdated and still runs without a sandbox, with many web security protections disabled. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: New Dysphoria DDoS botnet spreads to 200k devices worldwideArtifactory flaws chained in attacks deploying backdoor malwareAI-powered attack exploited PaperCut flaws to hack 395 organizationsCisco FMC flaws exploited by ransomware gang, state-sponsored hackersNew 'BlueMoon' kit exploited Windows and Chrome zero-day flaws","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F09\u002F11\u002Frabbit.jpg","2026-09-13T14:26:32+00:00","2026-09-13T16:00:12.554291+00:00",9,[18,21,24,27],{"name":19,"type":20},"Sogou Input Method","product",{"name":22,"type":23},"Tencent","vendor",{"name":25,"type":26},"UNC3569","threat_actor",{"name":28,"type":29},"Chromium","technology","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":30,"icon":32,"name":33,"slug":34},null,"Malware","malware",[36,41,46,48],{"category":37},{"id":38,"icon":32,"name":39,"slug":40},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":42},{"id":43,"icon":32,"name":44,"slug":45},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":47},{"id":30,"icon":32,"name":33,"slug":34},{"category":49},{"id":50,"icon":32,"name":51,"slug":52},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[54,58],{"type":55,"value":56,"context":57},"cve","CVE-2026-51990","Critical vulnerability in Tencent's Sogou Input Method for Windows exploited by UNC3569.",{"type":34,"value":59,"context":60},"GrayRabbit","Backdoor malware deployed by UNC3569."]