{"id":81536,"date":"2026-09-13T13:46:13","date_gmt":"2026-09-13T17:46:13","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=81536"},"modified":"2026-09-13T13:46:13","modified_gmt":"2026-09-13T17:46:13","slug":"tencent-sogou-grayrabbit-malware-exploit-81536","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/tencent-sogou-grayrabbit-malware-exploit-81536\/","title":{"rendered":"Tencent Sogou Flaw Lets Hackers Deploy GrayRabbit Malware"},"content":{"rendered":"<p>Earlier this year, a sophisticated cyberespionage campaign unfolded with a single click. Researchers at <a href=\"https:\/\/www.gendigital.com\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Gen Digital<\/a> have uncovered an active exploitation campaign in which threat actors from a China-aligned group, tracked as UNC3569, weaponized a critical one-click remote code execution vulnerability in Tencent\u2019s Sogou Input Method for Windows to deploy the GrayRabbit backdoor. This targeted attack chain, enabled by CVE-2026-51990, exploits three distinct weaknesses in the software, turning a popular Chinese typing tool into a silent gateway for espionage.<\/p>\n<h2>Unpacking the Vulnerability: A Chain of Three Failures<\/h2>\n<p>The Sogou Input Method is not merely a keyboard utility. It is an integral piece of software for hundreds of millions of Windows users in China, allowing them to type Chinese characters with a standard keyboard. Developed by the Chinese tech giant Tencent, its deep integration into the operating system includes a custom URI protocol handler and an embedded web browser built on an outdated Chromium 80 engine.<\/p>\n<p>Gen Threat Labs reports that the attack <a href=\"https:\/\/overcentral.com\/en\/ai-search-cognitive-load-78133\/\" title=\"AI Search Moves Cognitive Load, Does Not Remove It\" data-iacss-internal=\"1\">does not<\/a> rely on a single exploit. Instead, UNC3569 masterfully chains three separate security weaknesses in the product to achieve its goal. The first link in this chain is an unvalidated command-line argument injection vulnerability in the custom <strong>sgbiz:<\/strong> URI scheme. The second is an unrestricted URL navigation flaw in a Chromium Embedded Framework (CEF)-based webview. The third and final component is the use of an outdated Chromium 80 engine that runs without a sandbox and with many critical web security protections disabled.<\/p>\n<h3>The Step-by-Step Attack Chain<\/h3>\n<p>The exploitation begins when a victim clicks a carefully crafted <strong>sgbiz:<\/strong> custom URI. This action triggers Windows to invoke the Sogou <strong>biz_helper.exe<\/strong> protocol handler. Critically, this handler passes the attacker-controlled command-line arguments from the URI directly to the legitimate <strong>SGMyInput.exe<\/strong> executable without any validation. This initial injection is the foundational flaw.<\/p>\n<p>These injected arguments then instruct the software to open its skincenter component. This component contains an embedded Chromium webview, which is then instructed to navigate to a URL controlled by the attacker. Because Sogou does not restrict the URL\u2019s scheme or destination, the attacker can point the browser to any malicious website. This is the second weakness: unrestricted navigation.<\/p>\n<p>In the final phase, the malicious webpage loaded by the attacker exploits a known vulnerability in the outdated Chromium 80 engine. Because this browser subprocess operates without a sandbox\u2014a standard security isolation technique used by modern browsers\u2014the exploit can directly achieve code execution on the host system. Once this foothold is secured, the payload installs the GrayRabbit backdoor.<\/p>\n<h2>What Is the GrayRabbit Malware?<\/h2>\n<p>The GrayRabbit backdoor is not a new malware family. In 2024, researchers from Google provided the first detailed analysis of GrayRabbit, linking it definitively to the threat actor UNC3569. They described it as a modular malware family operating within a complex ecosystem that blurs the lines between cybercrime and state-sponsored cyber contracting.<\/p>\n<p>The specific sample analyzed by Gen Threat Labs represents a significant evolution. It is a 64-bit variant with a more extensive command set compared to earlier builds. The malware communicates with its command-and-control (C2) servers using an RC4-encoded configuration. Its capabilities are comprehensive and include executing arbitrary processes, opening interactive reverse shells, uploading and downloading files, collecting detailed system and user information, and reflectively loading plugins directly into the host\u2019s memory without writing them to disk.<\/p>\n<h2>Tencent\u2019s Response and the Lingering Risk<\/h2>\n<p>Gen Threat Labs responsibly disclosed its findings to Tencent on April 9. The software vendor responded by deploying a fix in Sogou Input Method version 16.3.0.3498, which was released on April 21. The patch specifically addresses the first two weaknesses in the attack chain. It now validates the URL arguments accepted through the <strong>sgbiz:<\/strong> protocol handler, permits only HTTPS connections, and restricts navigation to a whitelist of approved domains related to Sogou and Tencent.<\/p>\n<p>However, the researchers issued a critical warning that the patch does not fully resolve the underlying risk. The embedded Chromium 80 browser engine remains outdated and critically continues to run without a sandbox. Many web security protections also remain disabled. This means that while the specific initial attack vector has been closed, the software\u2019s core architecture still presents a significant and exploitable attack surface for other methods of compromise.<\/p>\n<h2>How Does the Sogou Input Method Become a Security Risk?<\/h2>\n<p>To understand the severity of this vulnerability, one must appreciate the application&#8217;s privileged position in the operating system. Sogou Input Method, by its nature as an input method editor, requires deep hooks into the kernel and user interfaces of Windows. Its custom URI handler allows it to be invoked by any application or link, bridging the gap between web content and native code execution. When this bridge is not properly secured, a simple link click can escalate to full system compromise. The embedded browser, designed for convenience to render settings and skins, becomes a liability when its engine is not maintained with the same rigor as a standalone browser like Chrome or Edge.<\/p>\n<h2>What Are the Broader Implications for Enterprise Security?<\/h2>\n<p>For enterprises with a global footprint, especially those operating in or with partners in China, this incident serves as a stark reminder that widely installed consumer software can become an overlooked backdoor. The Sogou Input Method is not typically managed by enterprise IT teams, yet its vulnerabilities can be exploited to gain a foothold in a network. The attack highlights the danger of supply chain risk and the need for organizations to consider the security posture of every application installed on their endpoints, not just those deemed &#8220;enterprise-grade.&#8221; The fact that the browser engine remains unsandboxed even after the patch indicates a fundamental architectural choice by Tencent that may be difficult to reverse, creating a persistent potential vulnerability.<\/p>\n<h2>The Threat Actor: Understanding UNC3569<\/h2>\n<p>UNC3569 is a sophisticated threat actor that Google researchers have linked to China. They operate in a dual-capacity, engaging in both financially motivated cybercrime and as contractors for espionage campaigns. This blend of motivations makes them particularly dangerous. Their toolset, GrayRabbit, is modular and under constant development, as evidenced by the 64-bit upgrade. The use of a one-click exploit against a widely used application suggests a focused effort to compromise high-value targets, likely in sectors such as government, technology, and defense, where users might plausibly be targeted with the specific <strong>sgbiz:<\/strong> URI.<\/p>\n<h2>A Delicate Balance Between Usability and Security<\/h2>\n<p>This situation encapsulates a classic tension in software design, particularly for consumer applications in large markets. Tencent\u2019s Sogou Input Method is a highly integrated utility that offers a seamless user experience. The custom URI scheme and embedded browser are features designed for convenience. However, the security compromises made to achieve that convenience\u2014the use of an outdated browser engine and the disabling of sandboxing\u2014have created a dangerous vulnerability. The patch is a reactive measure that closes a specific hole, but the architectural risk remains. Users and IT administrators must ask whether the convenience of a deeply integrated typing tool outweighs the implicit security risks of running an unsandboxed, outdated browser engine on their systems.<\/p>\n<h2>Recommendations for Mitigation and Awareness<\/h2>\n<p>For any organization with a significant presence in China or employing Chinese-speaking staff, immediate action is warranted. First, verify that Sogou Input Method is updated to version 16.3.0.3498 or later. However, updating alone is insufficient. IT security teams should conduct a thorough inventory of all endpoints to identify where this software is installed. Given that the underlying browser engine remains a risk, security teams should consider implementing application control or advanced endpoint detection and response (EDR) rules that can flag suspicious behavior originating from the <strong>SGMyInput.exe<\/strong> or <strong>biz_helper.exe<\/strong> processes. User awareness training should also be updated. Users should be cautioned against clicking on unexpected links, even if they appear to be related to system software. The exploitation of a legitimate URI scheme means that a seemingly mundane click can have catastrophic consequences.<\/p>\n<h2>Looking at the Future of the Sogou Input Method<\/h2>\n<p>Tencent now faces a significant challenge. While the immediate vulnerability has been patched, the fundamental reliance on an outdated Chromium engine represents a ticking clock. As new browser vulnerabilities are discovered and exploited, the Sogou Input Method will remain a prime target. The company will need to decide whether to invest in a major architectural overhaul\u2014porting its skin rendering and other web-based features to a modern, sandbox-capable engine\u2014or to continue with a reactive patching strategy that leaves users at risk. <a href=\"https:\/\/overcentral.com\/en\/for-the-stars-space-exploration-game-78319\/\" title=\"For The Stars Reveals Vast Universe to Explore and Settle\" data-iacss-internal=\"1\">For the<\/a> security community, the GrayRabbit campaign is a definitive example of how a sophisticated threat actor can combine social engineering with a multi-stage technical exploit to compromise a system through a seemingly benign application. It underscores that in modern cybersecurity, the weakest link is often the one that users trust the most.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Earlier this year, a sophisticated cyberespionage campaign unfolded with a single click. Researchers at Gen Digital have uncovered an active exploitation campaign in which threat actors from a China-aligned group, tracked as UNC3569, weaponized a critical one-click remote code execution vulnerability in Tencent\u2019s Sogou Input Method for Windows to deploy the GrayRabbit backdoor. This targeted [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":83302,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/81536.png","fifu_image_alt":"Tencent Sogou Flaw Lets Hackers Deploy GrayRabbit Malware","footnotes":""},"categories":[31],"tags":[],"class_list":["post-81536","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/81536.png","fifu_image_alt":"Tencent Sogou Flaw Lets Hackers Deploy GrayRabbit Malware","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/81536","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=81536"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/81536\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/83302"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=81536"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=81536"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=81536"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}