China-Linked UNC3569 Exploits Sogou Input Method Vulnerability to Deploy GRAYRABBIT Backdoor
A China-linked hacking group exploited a vulnerability in Sogou Input Method's Windows browser engine to deploy the GRAYRABBIT backdoor, leveraging outdated Chromium components and unfiltered command-line arguments. The attack chain involved a crafted link that bypassed security measures, allowing remote code execution and persistence through a malicious DLL embedded in the input method's settings.
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday.
The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns
*** END OF TRANSMISSION ***