discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

A China-aligned espionage group, UNC3569, is actively exploiting a critical remote code execution flaw (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor.

By Bill Toulas·Sep 13·bleepingcomputer.com·3 min read

Intelligence analysis by Gemini 2.5 Flash

Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Image: bleepingcomputer.com

Cybersecurity researchers at Gen Digital have identified that the UNC3569 threat group is leveraging a one-click remote code execution vulnerability in Tencent's widely used Sogou Input Method. The attack chain involves a crafted URI, unvalidated command-line arguments, and an outdated Chromium engine, ultimately leading to the installation of the sophisticated GrayRabbit malware.

Why it matters

This story matters to security professionals as it highlights the exploitation of a popular application by a state-aligned group, demonstrating advanced persistent threat (APT) tactics and the risks associated with outdated embedded components in widely used software.

Imagine a special keyboard app on your computer that helps you type in different languages. Bad guys found a secret trick in this app, like a hidden door, that lets them sneak in. When you click a special link, the app accidentally opens a tiny, old web browser inside itself that isn't very safe. This lets the bad guys put a secret spy program, called GrayRabbit, onto your computer without you knowing, which can then steal your information or control your computer.

Analysis

Threat actors associated with the China-aligned espionage group UNC3569 have been observed actively exploiting a critical vulnerability, identified as CVE-2026-51990, within Tencent's Sogou Input Method for Windows. This security flaw is a one-click remote code execution (RCE) vulnerability, making it particularly dangerous as it requires minimal user interaction to trigger. The exploitation chain is sophisticated, leveraging multiple weaknesses within the application to achieve its objective of deploying the GrayRabbit backdoor. This incident underscores the persistent threat posed by state-sponsored groups targeting popular software with large user bases, especially those with embedded, potentially outdated, components.

UNC3569

UNC3569 is a threat group that Google researchers previously linked to a modular malware family known as GrayRabbit in 2024. This group is identified as a China-based actor operating across both cybercrime and cyber contractor-for-hire ecosystems, indicating a versatile and well-resourced adversary. Their operational methodology in this campaign involves chaining together multiple vulnerabilities rather than relying on a single exploit, showcasing a high level of technical proficiency and strategic planning. The group's ability to identify and weaponize complex attack chains in widely used software like Sogou Input Method highlights their advanced capabilities and the significant threat they pose to users and organizations.

Sogou Input Method

Tencent's Sogou Input Method is a highly popular Windows application, reportedly installed on hundreds of millions of devices in China, designed to facilitate typing Chinese characters. The attack chain exploited by UNC3569 specifically targets three weaknesses within this product. Firstly, it leverages an unvalidated command-line argument injection in the sgbiz: URI, allowing attackers to pass malicious arguments. Secondly, it exploits an unrestricted URL navigation capability within the application's CEF-based webview. Finally, the attack capitalizes on an outdated and unsandboxed Chromium browser engine embedded within Sogou, which runs with important web-security protections disabled. This combination of flaws creates a critical pathway for remote code execution, demonstrating the dangers of integrating third-party components without rigorous security updates and sandboxing.

GrayRabbit

GrayRabbit is a modular malware family that has been linked to the UNC3569 threat group. The sample analyzed by Gen Threat Labs in this campaign represents a more mature 64-bit variant, indicating ongoing development and refinement by its operators. This advanced version boasts an expanded command set and utilizes RC4-encoded command-and-control (C2) configurations, enhancing its stealth and resilience. The capabilities of GrayRabbit are extensive, including the ability to execute processes, open interactive reverse shells for direct system access, upload and download files, collect comprehensive system and user information, and reflectively load plugins directly into the host's memory. These features make GrayRabbit a potent tool for espionage, data exfiltration, and persistent access to compromised systems.

Key points

  • A China-aligned espionage group, UNC3569, is exploiting CVE-2026-51990 in Tencent's Sogou Input Method.
  • The vulnerability is a one-click remote code execution (RCE) flaw used to deploy the GrayRabbit backdoor.
  • The attack chains three weaknesses: unvalidated command-line arguments, unrestricted URL navigation, and an outdated, unsandboxed Chromium engine.
  • GrayRabbit is a modular 64-bit malware with capabilities for process execution, reverse shells, file transfer, and system information collection.
  • Tencent released a patch (version 16.3.0.3498) on April 21, but the embedded browser remains outdated and unsandboxed.
The Upside

Tencent has already released a patch (version 16.3.0.3498) for Sogou Input Method, addressing the critical URL argument validation flaw and restricting navigation to approved domains. This swift action helps protect users who update their software, mitigating the immediate threat posed by this specific attack chain.

The Downside

Despite the patch, researchers warn that the underlying Chromium browser engine within Sogou Input Method remains outdated and continues to run without a sandbox, with many web security protections disabled. This leaves the application vulnerable to future exploits targeting the embedded browser, requiring users to remain vigilant and for Tencent to implement more comprehensive security updates.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritymalwarevulnerabilitychinaespionagetencentgrayrabbitunc3569

Author

Bill Toulas

Intelligence analysis by

Gemini 2.5 Flash

Published

Sep 13, 2026

Source

bleepingcomputer.com

Share

Topics

securitymalwarevulnerabilitychinaespionagetencentgrayrabbitunc3569

Related

More from this desk

Oct 7·thehackernews.com

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, including a serious SSRF bug rated 10.0 on the CVSS scale.

Oct 7·bleepingcomputer.com

Microsoft Outlook to block MSIX attachments starting November

Microsoft Outlook to block MSIX attachments starting November 2026.

Oct 7·bleepingcomputer.com

PoeLLM malware infects exposed AI servers in cryptomining attacks

PoeLLM malware targets exposed AI servers, using a poem for C2 addresses. Researchers found 3,400 compromised servers, with activity peaking at 800 infected systems.

Oct 7·bleepingcomputer.com

Ransomware has a new target. Is your backup ready?

Ransomware groups are targeting backups, making them a new threat. IT leaders need to secure their backups to prevent data loss.