China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

A China-linked threat actor has been exploiting a critical vulnerability in Sogou Input Method, a widely used input software on Chinese devices, to deploy a sophisticated backdoor known as GRAYRABBIT. The attack vector, attributed to UNC3569, marks a significant escalation of cyber threats targeting the Asian region.

The Sogou Input Method is a popular keyboard layout tool developed by Sogou Inc., a leading Chinese tech company. The software allows users to input non-standard characters and languages on their devices. However, researchers have discovered that a vulnerability in the application’s API can be exploited to gain unauthorized access to sensitive data and execute malicious code.

The GRAYRABBIT backdoor is a highly advanced tool used for maintaining persistence on compromised systems. Once deployed, it allows attackers to remotely access and control infected devices, enabling them to conduct further attacks or gather sensitive information. The threat actor’s ability to inject the backdoor into compromised systems highlights the severity of the vulnerability.

The UNC3569 group’s tactics are particularly concerning due to their sophistication and stealth. Unlike many other threat actors, who often rely on brute-force attacks or phishing schemes, UNC3569 is using a zero-day exploit in Sogou Input Method. This means that no patch or fix has been released yet to address the vulnerability. As a result, users of the software are highly vulnerable to attack until an update is made available.

The implications of this attack vector extend beyond mere technical complexity. The exploitation of a widely used input tool by a nation-state actor raises concerns about data sovereignty and the potential for large-scale surveillance. Given the widespread use of Sogou Input Method in China, it is likely that many individuals and organizations have been impacted by this vulnerability.

In light of these findings, users are advised to take immediate action to protect themselves. First and foremost, update your software regularly to ensure you have the latest security patches. When using input tools like Sogou Input Method, choose options that limit data collection and transmission. Finally, be cautious when receiving unsolicited software updates or notifications, as these may be attempts by threat actors to exploit vulnerabilities on your device. By staying vigilant and taking proactive measures, users can significantly reduce their risk of falling victim to sophisticated cyber threats like GRAYRABBIT.


Source: The Hacker News — 2026-09-11