The discovery of a critical security vulnerability within the Sogou Input Method, a ubiquitous software utility used by hundreds of millions of Chinese speakers globally, has sent ripples through the cybersecurity community. Researchers at Gen Digital identified that a China-affiliated threat actor, tracked as UNC3569, successfully weaponized a flaw in the software’s architecture to gain unauthorized remote access to user systems. By exploiting the application’s custom URL handling mechanism, attackers were able to bypass standard security protocols and deploy a sophisticated backdoor known as GRAYRABBIT.
This incident highlights the inherent risks associated with widely deployed software that integrates outdated browser components and lacks robust sandboxing. While Tencent, the parent company of Sogou, issued a patch in April 2026 to mitigate the immediate attack vector, security experts remain concerned about the underlying architectural deficiencies that persist within the software.
The Anatomy of the Attack: A Technical Breakdown
The attack vector identified by Gen Digital relies on the way the Windows version of Sogou Input Method manages its internal components. The software utilizes a custom URL scheme, sgbiz:, to facilitate communication between various modules. When a user interacts with a link formatted with this protocol, the Windows operating system routes the request to biz_helper.exe. This executable is responsible for interpreting the link and launching the appropriate Sogou component.
Critically, the investigation revealed that biz_helper.exe failed to perform adequate validation on command-line arguments passed through these sgbiz: links. Attackers leveraged this oversight to pass malicious parameters to SGMyInput.exe, the application’s settings manager. Specifically, the exploit forced the application to open its "skin store"—the only interface within the program that initializes a web browser—and navigate to a URL of the attacker’s choosing.
The browser window invoked by this process is built upon an antiquated version of the Chromium engine, specifically version 80, which dates back to March 2020. More concerning is the fact that core security features, such as the browser sandbox and the same-origin policy, were explicitly disabled in the application’s configuration. Without the sandbox, a malicious web page could execute arbitrary code directly on the host machine, inheriting the privileges of the logged-in user.

Chronology and Identification of UNC3569
The threat actor behind this campaign, UNC3569, has been under the observation of Google Threat Intelligence and other security agencies since 2021. The group is categorized as a "hacker-for-hire" entity, frequently operating within the sphere of Chinese cyber-espionage. Their primary targets include government entities, educational institutions, financial firms, and technology companies, with a heavy concentration of operations in East and Southeast Asia.
The GRAYRABBIT backdoor, the payload delivered during this campaign, is a modular toolset that has been part of the group’s arsenal for several years. It functions as a foundational implant, establishing a remote command shell, enabling bidirectional file exfiltration, and allowing the attacker to download additional malicious modules from a remote command-and-control (C2) server.
The timeline of the current disclosure is as follows:
- 2020–2021: The integration of the vulnerable Chromium 80 engine into Sogou Input Method.
- November 2021: CVE-2021-38003, a high-severity vulnerability in Chrome’s V8 JavaScript engine, is added to the CISA Known Exploited Vulnerabilities catalog.
- December 2022: Security firm STAR Labs publishes comprehensive documentation and functional exploit code for CVE-2021-38003.
- Early 2026: UNC3569 actively utilizes the Sogou vulnerability in live intrusion campaigns.
- April 9, 2026: Gen Digital reports the security flaw to Tencent.
- April 21, 2026: Tencent releases version 16.3.0.3498, patching the URL-handling flaw.
Broader Context: The Scale of Exposure
The prevalence of Sogou Input Method makes this vulnerability particularly significant. According to research conducted by the University of Toronto’s Citizen Lab in 2023, the software maintains a monthly active user base exceeding 455 million individuals across Windows, Android, and iOS platforms. It commands roughly 70% of the Chinese-language input method market. While the user base is predominantly located within mainland China, the software is also utilized by significant populations in the United States and other international regions, creating a massive potential attack surface.
The security implications are compounded by previous findings from Citizen Lab, which identified encryption flaws in the software that could allow third parties to intercept and decrypt the keystrokes of users. The convergence of these vulnerabilities—keystroke interception and the ability to deploy remote backdoors—positions Sogou as a high-value target for both surveillance and persistent unauthorized access.
Official Responses and Patch Efficacy
Following the disclosure by Gen Digital, Tencent moved to address the vulnerability, which was formally assigned the identifier CVE-2026-51990. The company’s response focused on hardening the biz_helper.exe component. The patched version now implements strict validation for web-address arguments, limiting them to HTTPS protocols and verifying that the destination hostname belongs to an approved whitelist of domains, including sogou.com and qq.com.

However, the efficacy of this patch has been debated by security researchers. While the update successfully closes the specific "one-click" link-handling exploit, it fails to address the underlying vulnerability of the outdated Chromium 80 engine. As of the latest update, the browser component remains un-sandboxed and continues to operate with disabled security flags. If an attacker identifies a new method to trigger the browser component without relying on the sgbiz: protocol, the fundamental risk of code execution remains.
Tencent has maintained that the attack chain is "relatively complex" and requires social engineering, asserting that a user would need to actively authorize a browser pop-up prompt to complete the infection. Conversely, Gen Digital emphasizes that the initial click is the primary risk factor and that, in many scenarios, users are conditioned to ignore such prompts or are misled by the context of the link delivery.
Implications for Enterprise and Consumer Security
The use of GRAYRABBIT via an exploited legitimate application underscores a growing trend in cyber warfare: the "living-off-the-land" approach. By exploiting trusted software, attackers can bypass traditional endpoint detection and response (EDR) systems that might otherwise flag unknown binaries.
The technical steps taken by the attackers to evade detection were notably sophisticated. After the downloader pulled a legitimate copy of 7-Zip, a malicious DLL, and an encrypted payload, the system performed a "process count" check. If the machine was running fewer than 50 processes—a characteristic common in automated malware-analysis sandboxes—the payload would intentionally fail to decrypt, effectively masking its purpose from security researchers. Furthermore, the malware utilized NTFS alternate data streams to hide its footprint and performed "self-deletion" to leave no traces in standard system logs.
Recommendations for Mitigation
For users and organizations that continue to rely on Sogou Input Method, immediate action is required to ensure that the application is updated to version 16.3.0.3498 or later. While the patch mitigates the known entry vector, organizations should consider the following security practices:
- Network Monitoring: Monitor for traffic patterns associated with the GRAYRABBIT C2, specifically non-TLS traffic occurring on port 443, which is typically reserved for encrypted communication.
- Endpoint Hardening: Implement strict application control policies to restrict the execution of unauthorized DLLs or tools within public directories like
C:UsersPublicDocuments. - Risk Assessment: Given the history of vulnerabilities in this specific software, organizations with high-security requirements should evaluate whether the utility aligns with their internal risk management policies, particularly in environments handling sensitive data.
- Version Verification: Users should navigate to the software’s "About" or "Check for Updates" menu to confirm they are running the latest version, as the automated update mechanism is the primary defense against the known exploit.
As cyber-espionage groups continue to refine their tactics, the reliance on third-party software with deep system integration—especially those with legacy codebases—represents a persistent and evolving challenge. The Sogou incident serves as a critical reminder that even widely trusted applications can become conduits for sophisticated state-sponsored intrusions if security is not prioritized throughout the software development lifecycle.
