{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/unc3569/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["UNC3569"],"_cs_cpes":["cpe:2.3:a:tencent:sogou_input_method:*:*:*:*:*:windows:*:*","cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2021-38003"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Sogou Input Method (\u003c 16.3.0.3498)"],"_cs_severities":["high"],"_cs_tags":["backdoor","exploitation","cve-2026-51990","grayrabbit","unc3569"],"_cs_type":"threat","_cs_vendors":["Tencent"],"content_html":"\u003cp\u003eUNC3569, a China-linked hacker-for-hire group, has been observed exploiting a vulnerability (CVE-2026-51990) in the Sogou Input Method to deploy the GRAYRABBIT backdoor on Windows systems. The attack chain leverages the application's 'sgbiz:' protocol handler, which failed to sanitize command-line arguments. By passing malicious arguments to the 'biz_helper.exe' component, attackers forced an internal, outdated (Chromium 80, circa 2020), and sandbox-disabled browser component to visit an attacker-controlled site. This site delivered an exploit for CVE-2021-38003, enabling arbitrary code execution. The final payload, GRAYRABBIT, is a modular backdoor known to the threat actor for years, which performs process enumeration and exfiltration via non-TLS traffic on port 443. Tencent released a patch in version 16.3.0.3498 in April 2026. Defenders should note that while the patch prevents the argument injection, the underlying browser component remains significantly outdated.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker convinces a user to click a crafted link using the 'sgbiz:' protocol handler.\u003c/li\u003e\n\u003cli\u003eWindows passes the link to 'biz_helper.exe', which fails to validate command-line arguments.\u003c/li\u003e\n\u003cli\u003eThe handler executes 'SGMyInput.exe' with parameters pointing to an attacker-controlled URL via the application's internal Chromium-based 'skin store' window.\u003c/li\u003e\n\u003cli\u003eThe outdated Chromium v80 component, running without sandbox protections, loads a webpage containing an exploit for CVE-2021-38003.\u003c/li\u003e\n\u003cli\u003eThe V8 engine exploit triggers arbitrary code execution in the context of the user.\u003c/li\u003e\n\u003cli\u003eA downloader is executed, fetching a malicious DLL and encrypted payload from an Alibaba Cloud staging server (8.218.50.207) into 'C:\\Users\\Public\\Documents'.\u003c/li\u003e\n\u003cli\u003eThe system's '7-Zip' utility is launched, triggering DLL sideloading of the malicious DLL disguised as a legitimate 7-Zip component.\u003c/li\u003e\n\u003cli\u003eThe GRAYRABBIT backdoor (core.dll) initializes, performs process checks, and begins communication with 'mail.uaiubifas.top' over port 443 using RC4-scrambled traffic.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated remote code execution with user privileges. Given Sogou Input Method's massive user base, exceeding 455 million monthly users with significant deployments in government, education, finance, and technology sectors in East and Southeast Asia, the potential for widespread compromise is significant. Successful exploitation grants attackers persistent access to sensitive data, file exfiltration capabilities, and the ability to load additional malicious modules.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of Sogou Input Method to version 16.3.0.3498 or later immediately.\u003c/li\u003e\n\u003cli\u003eBlock the identified C2 domain 'mail.uaiubifas.top' and the staging IP '8.218.50.207' at the network perimeter.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect the specific process-creation pattern of 'biz_helper.exe' launching 'SGMyInput.exe' with unexpected URL parameters.\u003c/li\u003e\n\u003cli\u003eMonitor for non-TLS traffic on port 443, which may indicate GRAYRABBIT command and control activity.\u003c/li\u003e\n\u003cli\u003eHunt for artifacts in 'C:\\Users\\Public\\Documents' consistent with the 7-Zip DLL sideloading technique.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-11T08:29:40Z","date_published":"2026-09-11T08:29:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sogou-grayrabbit/","summary":"UNC3569 exploited a command-line argument injection flaw in Sogou Input Method to trigger an insecure Chromium component and execute the GRAYRABBIT backdoor.","title":"UNC3569 Exploitation of Sogou Input Method to Deploy GRAYRABBIT Backdoor","url":"https://feed.craftedsignal.io/briefs/2026-09-sogou-grayrabbit/"}],"language":"en","title":"CraftedSignal Threat Feed - Unc3569","version":"https://jsonfeed.org/version/1.1"}