CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7067

As cited

Copy frozen at (site build).

threat intel

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

China-linked threat actor UNC3569 exploited a vulnerability in Sogou Input Method, a widely used Chinese character typing tool for Windows, to deploy the GRAYRABBIT backdoor. The attack chain began with a crafted link and resulted in attackers gaining privileges equivalent to the compromised user account. Tencent, which owns Sogou, was involved in the response.

Why it matters: Organizations and individuals using Sogou Input Method on Windows are at risk of backdoor installation and full user-level compromise; patching or disabling the application should be prioritized if exploitation activity is confirmed in your environment.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary