A critical vulnerability in Tencent’s Sogou Input Method for Windows has been exploited by Chinese-aligned threat actors to deploy a sophisticated backdoor malware known as GrayRabbit. The security flaw, identified as CVE-2026-51990, allows attackers to execute malicious code with just one click, putting hundreds of millions of users at risk.
The vulnerability is being actively exploited in the wild by the UNC3569 threat group, which has been linked to various espionage and cybercrime activities. Gen Digital’s researchers have revealed that the attack chain involves chaining three weaknesses in the Sogou Input Method: an unvalidated command-line argument injection, unrestricted URL navigation, and an outdated Chromium browser engine. The attackers use a crafted link to inject malicious arguments into the legitimate SGMyInput.exe executable, which then loads an attacker-controlled URL in the embedded Chromium webview.
Once the victim clicks on the malicious link, the attackers exploit a known vulnerability in Sogou’s outdated Chromium 80 engine to gain code execution and install the GrayRabbit backdoor. The malware sample analyzed by Gen Threat Labs is a mature 64-bit variant with an expanded command set and RC4-encoded C2 configuration. Its capabilities include process execution, opening reverse shells, uploading and downloading files, collecting system and user information, and loading plugins in the host’s memory.
The Sogou Input Method has hundreds of millions of installations in China, making it a significant target for attackers. The vulnerability was reported to Tencent by Gen Digital on April 9, and a patch was released on April 21. However, the researchers warned that the underlying browser remains outdated and lacks essential security protections, leaving users vulnerable to attacks.
The GrayRabbit malware has been linked to UNC3569 in previous incidents, and its capabilities suggest a high level of sophistication. The fact that attackers are exploiting this vulnerability to deploy such a sophisticated backdoor highlights the need for organizations to prioritize patching and updating their software regularly. Users should also be cautious when clicking on links from unknown sources and ensure that their browsers are up-to-date with the latest security patches.
In conclusion, the exploitation of the Sogou Input Method vulnerability is a stark reminder of the importance of staying vigilant in today’s cybersecurity landscape. Users and organizations must prioritize patching and updating their software regularly to prevent attacks like this one from succeeding.
Source: Bleeping Computer — 2026-09-13