Hackers exploit Tencent app flaw to deploy GrayRabbit malware (opens in a new tab)
Why readA one-click RCE chain in Sogou Input Method, an app with hundreds of millions of Windows installs in China, is under active exploitation by UNC3569 to plant the GrayRabbit backdoor.
Gen Threat Labs reports that UNC3569, a China-aligned espionage group, is chaining three weaknesses in Tencent's Sogou Input Method for Windows, tracked as CVE-2026-51990. The entry point is an unvalidated command-line argument injection in the sgbiz: custom URI handler, which Windows passes to biz_helper.exe when a victim clicks a crafted link; the product also ships a built-in browser on an outdated Chromium engine. Successful exploitation delivers the GRAYRABBIT backdoor with a single click and no further user interaction.