Threat actors linked to UNC3569 are exploiting CVE-2026-51990 in Tencent’s Sogou Input Method for Windows to deliver the GrayRabbit backdoor through a crafted link. Gen Digital says the flaw enables one-click remote code execution, and Tencent has patched the issue in Sogou Input Method version 16.3.0.3498. #UNC3569 #GrayRabbit #Tencent #SogouInputMethod #CVE-2026-51990
Keypoints
- UNC3569 is exploiting a critical flaw in Sogou Input Method for Windows.
- The attack begins with a crafted sgbiz: URI clicked by the victim.
- The chain abuses command-line injection, unrestricted URL navigation, and an outdated Chromium engine.
- The exploit installs the GrayRabbit backdoor with code execution on the target system.
- Tencent fixed the issue in version 16.3.0.3498, but the browser remains unsandboxed and outdated.