Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The Guardian view on the government’s corporate reforms: entrenching neoliberalism, not ending it | Editorial

    September 13, 2026

    Trump downplays AI risks after dire expert warnings and calls to slow development down

    September 13, 2026

    Trump calls on Ukraine to halt attacks on Russian oil refineries – POLITICO

    September 13, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Guardian view on the government’s corporate reforms: entrenching neoliberalism, not ending it | Editorial
    • Trump downplays AI risks after dire expert warnings and calls to slow development down
    • Trump calls on Ukraine to halt attacks on Russian oil refineries – POLITICO
    • First ministers at Celtic summit to affirm right to seek independence from the UK | Devolution
    • Russia struck train near Poland border shortly after Boris Johnson and top European officials passed through
    • TechCrunch Mobility: Lyft has entered the robotaxi chat
    • Hackers exploit Tencent app flaw to deploy GrayRabbit malware
    • LDK 0.2.6 fixes Lightning fund diversion and restart bugs
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, September 13
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers exploit Tencent app flaw to deploy GrayRabbit malware

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 13, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor.

    Researchers at cybersecurity company Gen Digital warn that the security issue is a one-click remote code execution (RCE) flaw.

    “We observed this vulnerability actively exploited in the wild by the UNC3569 threat group to deploy the GRAYRABBIT backdoor through a crafted link,” Gen Threat Labs says.

    Sogou Input Method is a popular Windows application that lets users type Chinese characters using a standard keyboard and also offers a custom link handler and a built-in web browser using an outdated Chromium engine.

    Developed by Chinese tech giant Tencent, Sogou Input Method reportedly has hundreds of millions of installations in China.

    Gen Threat Labs reports that UNC3569 chains three weaknesses in the product:

    1. an unvalidated command-line argument injection in the sgbiz: URI
    2. an unrestricted URL navigation in a CEF-based webview
    3. an outdated, unsandboxed Chromium browser engine

    The attack chain starts with the victim clicking a crafted sgbiz: custom URI, causing Windows to invoke Sogou’s biz_helper.exe protocol handler, which passes attacker-controlled command-line arguments to the legitimate SGMyInput.exe executable without validating them.

    The attacker-injected arguments open Sogou’s skincenter component and instruct its embedded Chromium webview to load an attacker-controlled URL. Sogou does not restrict the URL’s scheme or destination.

    In the third stage, a malicious page exploits a known vulnerability in Sogou’s outdated Chromium 80 engine. Because the browser runs without a sandbox and with important web-security protections disabled, the exploit achieves code execution and installs the GrayRabbit backdoor.

    Attack chain
    The UNC3569 attack chain
    Source: Gen Threat Labs

    In 2024, Google researchers described GrayRabbit as a modular malware family and linked it to UNC3569, a China-based threat actor operating across both the cybercrime and cyber contractor-for-hire ecosystems.

    The malware sample that Gen Threat Labs analyzed is a more mature 64-bit variant with an expanded command set and RC4-encoded command-and-control (C2) configuration.

    Its capabilities include process execution, opening interactive reverse shells, uploading and downloading files, collecting system and user information, and reflectively loading plugins in the host’s memory.

    Gen Threat Labs reported their findings to Tencent on April 9, and the software vendor deployed a fix in Sogou Input Method version 16.3.0.3498, released on April 21.

    The patch validates the URL arguments accepted through the protocol handler, permits only HTTPS, and restricts navigation to approved domains related to Sogou and Tencent.

    However, the researchers warned that the underlying browser remains outdated and still runs without a sandbox, with many web security protections disabled.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    app Deploy exploit Flaw GRAYRABBIT hackers Malware Tencent
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up

    Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

    Liquid Network Comes Back Online After Bitcoin Exploit

    Microsoft Excel KB5002914 update breaks copy and paste for some users

    Surfshark VPN says hackers breached internal testing, proxy servers

    Conti ransomware gang member sentenced to 4 years in prison

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The Guardian view on the government’s corporate reforms: entrenching neoliberalism, not ending it | Editorial

    September 13, 2026

    Trump downplays AI risks after dire expert warnings and calls to slow development down

    September 13, 2026

    Trump calls on Ukraine to halt attacks on Russian oil refineries – POLITICO

    September 13, 2026

    First ministers at Celtic summit to affirm right to seek independence from the UK | Devolution

    September 13, 2026
    Latest Posts

    Bridge collapse in DR Congo reignites debate about mining revenues

    August 3, 2026

    How many people die trying to cross the Channel in a small boat? – Full Fact

    August 3, 2026

    The Guardian view on events in Ceuta: chaos and tragedy are weaponised by the far right | Editorial

    August 3, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The Guardian view on the government’s corporate reforms: entrenching neoliberalism, not ending it | Editorial

    September 13, 2026

    Trump downplays AI risks after dire expert warnings and calls to slow development down

    September 13, 2026

    Trump calls on Ukraine to halt attacks on Russian oil refineries – POLITICO

    September 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.