As cited
Copy frozen at (site build).
threat intel
China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
China-linked threat actor UNC3569 exploited a vulnerability in Sogou Input Method, a widely used Chinese character typing tool for Windows, to deploy the GRAYRABBIT backdoor. The attack chain began with a crafted link and resulted in attackers gaining privileges equivalent to the compromised user account. Tencent, which owns Sogou, was involved in the response.
Why it matters: Organizations and individuals using Sogou Input Method on Windows are at risk of backdoor installation and full user-level compromise; patching or disabling the application should be prioritized if exploitation activity is confirmed in your environment.
- Source published
- First seen by Cybersecurity Tracker