Ethical Hacking News
A China-linked hacking group has exploited a flaw in the Sogou Input Method to deploy a backdoor on victims' computers, known as GRAYRABBIT. The attack highlights the importance of keeping software up to date and being cautious when opening links from unknown sources. In this article, we will delve into the details of the vulnerability, the threat posed by the backdoor, and the measures that can be taken to protect users.
The Sogou Input Method, a widely used tool for typing Chinese characters on Windows, has a vulnerability that allows a China-linked hacking group to deploy a backdoor on victims' computers. The vulnerability is exploited through a crafted link that opens a browser window vulnerable to the GRAYRABBIT backdoor. The GRAYRABBIT backdoor grants an attacker a remote command shell, allows file movement, and loads additional modules from the attacker's server. The attack was successful due to an outdated browser engine, but a fix was released by Tencent that blocked the attackers. The attack highlights the importance of keeping software up to date and being cautious when opening links from unknown sources.
The security community has been alerted to a concerning vulnerability in the Sogou Input Method, a widely used tool for typing Chinese characters on Windows. A China-linked hacking group, known as UNC3569, has exploited this flaw to deploy a backdoor on victims' computers, known as GRAYRABBIT. In this article, we will delve into the details of the vulnerability, the threat posed by the backdoor, and the measures that can be taken to protect users.
The vulnerability in question is a flaw in the Sogou Input Method's Windows version, which allows an attacker to install a backdoor on a victim's computer. The attack starts with a crafted link that is opened by the user, which then points to the Sogou settings program. The program is instructed to open a skin store with a web address of the attacker's choosing. This leads to the opening of a browser window, which is vulnerable to the GRAYRABBIT backdoor.
The GRAYRABBIT backdoor is a small program that allows an attacker to do anything the logged-in user could do. It gives an attacker a remote command shell, allows files to be moved in both directions, and can load additional modules from the attacker's server at any time. The backdoor is deployed through a malicious DLL that is installed on the victim's computer.
Tencent, the owner and developer of Sogou, fixed the flaw in April 2026, but the attack was still successful because the Sogou Input Method's browser engine was still using an outdated version of Chromium, which contained several known vulnerabilities. The browser engine was not patched, but the fix that was released by Tencent blocked the way in for the attackers.
The attack highlights the importance of keeping software up to date and being cautious when opening links from unknown sources. It also demonstrates the sophistication and persistence of China-linked hacking groups, who will stop at nothing to exploit vulnerabilities in software to gain access to sensitive information.
In this article, we will examine the details of the vulnerability, the threat posed by the GRAYRABBIT backdoor, and the measures that can be taken to protect users. We will also discuss the implications of this attack and the steps that can be taken to prevent similar attacks in the future.
Related Information:
https://www.ethicalhackingnews.com/articles/A-Sogou-Input-Method-Flaw-Exploited-to-Deploy-a-China-Linked-Backdoor-Understanding-the-Threat-ehn.shtml
https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html
Published: Fri Sep 11 03:18:16 2026 by llama3.2 3B Q4_K_M