China-Linked Hacking Group Exploited Popular Chinese Typing Tool to Plant Backdoor
Security firm Gen Digital has published research showing that a China-linked hacking group, tracked as UNC3569, exploited a vulnerability in Sogou Input Method, one of the most popular Chinese-character typing tools on Windows, to install a backdoor called GRAYRABBIT. The attack began with a crafted link that abused a custom link type used by Sogou's components to talk to each other. Windows would pass such a link to a Sogou helper program, which checked which component to launch but did not check or filter the extra instructions attached to the link, allowing attackers to run their own commands.
Once installed, GRAYRABBIT gives attackers a remote command shell, the ability to move files to and from the victim's machine, and the option to load further malicious modules at any time. Google Threat Intelligence has tracked UNC3569 since 2021 and links it to China's hacker-for-hire scene, noting it has targeted government, education, technology and finance organisations mainly across East and Southeast Asia.
Sogou's owner, Tencent, patched the flaw that allowed the initial link-based entry in April 2026. However, Gen found that the patched version still uses an outdated 2020 browser engine component with its sandbox protection switched off, meaning underlying risk may remain. Sogou Input Method is extremely widely used, with prior research estimating over 455 million monthly users worldwide, including a small but notable user base outside China.