Hackers exploit Tencent app flaw to deploy GrayRabbit malware
A China-aligned espionage group, UNC3569, is actively exploiting a critical remote code execution flaw (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor.
Intelligence analysis by Gemini 2.5 Flash

Cybersecurity researchers at Gen Digital have identified that the UNC3569 threat group is leveraging a one-click remote code execution vulnerability in Tencent's widely used Sogou Input Method. The attack chain involves a crafted URI, unvalidated command-line arguments, and an outdated Chromium engine, ultimately leading to the installation of the sophisticated GrayRabbit malware.
Imagine a special keyboard app on your computer that helps you type in different languages. Bad guys found a secret trick in this app, like a hidden door, that lets them sneak in. When you click a special link, the app accidentally opens a tiny, old web browser inside itself that isn't very safe. This lets the bad guys put a secret spy program, called GrayRabbit, onto your computer without you knowing, which can then steal your information or control your computer.
Analysis
Threat actors associated with the China-aligned espionage group UNC3569 have been observed actively exploiting a critical vulnerability, identified as CVE-2026-51990, within Tencent's Sogou Input Method for Windows. This security flaw is a one-click remote code execution (RCE) vulnerability, making it particularly dangerous as it requires minimal user interaction to trigger. The exploitation chain is sophisticated, leveraging multiple weaknesses within the application to achieve its objective of deploying the GrayRabbit backdoor. This incident underscores the persistent threat posed by state-sponsored groups targeting popular software with large user bases, especially those with embedded, potentially outdated, components.
UNC3569
UNC3569 is a threat group that Google researchers previously linked to a modular malware family known as GrayRabbit in 2024. This group is identified as a China-based actor operating across both cybercrime and cyber contractor-for-hire ecosystems, indicating a versatile and well-resourced adversary. Their operational methodology in this campaign involves chaining together multiple vulnerabilities rather than relying on a single exploit, showcasing a high level of technical proficiency and strategic planning. The group's ability to identify and weaponize complex attack chains in widely used software like Sogou Input Method highlights their advanced capabilities and the significant threat they pose to users and organizations.
Sogou Input Method
Tencent's Sogou Input Method is a highly popular Windows application, reportedly installed on hundreds of millions of devices in China, designed to facilitate typing Chinese characters. The attack chain exploited by UNC3569 specifically targets three weaknesses within this product. Firstly, it leverages an unvalidated command-line argument injection in the sgbiz: URI, allowing attackers to pass malicious arguments. Secondly, it exploits an unrestricted URL navigation capability within the application's CEF-based webview. Finally, the attack capitalizes on an outdated and unsandboxed Chromium browser engine embedded within Sogou, which runs with important web-security protections disabled. This combination of flaws creates a critical pathway for remote code execution, demonstrating the dangers of integrating third-party components without rigorous security updates and sandboxing.
GrayRabbit
GrayRabbit is a modular malware family that has been linked to the UNC3569 threat group. The sample analyzed by Gen Threat Labs in this campaign represents a more mature 64-bit variant, indicating ongoing development and refinement by its operators. This advanced version boasts an expanded command set and utilizes RC4-encoded command-and-control (C2) configurations, enhancing its stealth and resilience. The capabilities of GrayRabbit are extensive, including the ability to execute processes, open interactive reverse shells for direct system access, upload and download files, collect comprehensive system and user information, and reflectively load plugins directly into the host's memory. These features make GrayRabbit a potent tool for espionage, data exfiltration, and persistent access to compromised systems.
Key points
- A China-aligned espionage group, UNC3569, is exploiting CVE-2026-51990 in Tencent's Sogou Input Method.
- The vulnerability is a one-click remote code execution (RCE) flaw used to deploy the GrayRabbit backdoor.
- The attack chains three weaknesses: unvalidated command-line arguments, unrestricted URL navigation, and an outdated, unsandboxed Chromium engine.
- GrayRabbit is a modular 64-bit malware with capabilities for process execution, reverse shells, file transfer, and system information collection.
- Tencent released a patch (version 16.3.0.3498) on April 21, but the embedded browser remains outdated and unsandboxed.
Tencent has already released a patch (version 16.3.0.3498) for Sogou Input Method, addressing the critical URL argument validation flaw and restricting navigation to approved domains. This swift action helps protect users who update their software, mitigating the immediate threat posed by this specific attack chain.
Despite the patch, researchers warn that the underlying Chromium browser engine within Sogou Input Method remains outdated and continues to run without a sandbox, with many web security protections disabled. This leaves the application vulnerable to future exploits targeting the embedded browser, requiring users to remain vigilant and for Tencent to implement more comprehensive security updates.



