What happened
On September 11, 2026, public reporting described Gen Digital’s finding that UNC3569 had exploited the flaw to deploy GRAYRABBIT. Gen Digital reported CVE-2026-51990 to Tencent on April 9, 2026. Tencent distributed Sogou Input Method 16.3.0.3498 on April 21, 2026. The link-handler vulnerability is tracked as CVE-2026-51990 and was addressed in Sogou Input Method 16.3.0.3498.
The attack began with a crafted sgbiz: link that directed Sogou’s embedded browser towards attacker-controlled content. The exploited webview used CEF 80.1.16 and Chromium 80.0.3987.163 without normal sandbox protections, allowing the chain to reuse CVE-2021-38003. The delivery process placed a legitimate 7z.exe, a malicious 7z.dll and an encrypted payload in a public documents directory before DLL sideloading led to execution of the GRAYRABBIT implant.
Published hunt artefacts include SHA-256 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 for 7z.dll, 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e for payload p, and d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a for GRAYRABBIT core.dll; infrastructure includes mail.uaiubifas[.]top, noht1ng[.]top and 8.218.50[.]207, with C:\Users\Public\Documents\ used as a staging path.
GRAYRABBIT provides remote command execution, shell access, reconnaissance, file transfer and plugin-loading functions according to the cited research and reporting. The cited sources did not publish a victim count or a complete start-and-end window for the observed campaign. Attribution posture: Gen Digital attributes the observed intrusion to UNC3569 and describes the cluster as China-linked; no government attribution is cited.
Why this matters now
Input method editors are persistent, widely trusted desktop components that often escape standard enterprise software inventories, particularly in multinational organisations supporting Chinese-language users. The reported chain required a crafted link and then used Sogou’s custom protocol handler and embedded browser to obtain code execution as the logged-in Windows user. That creates access to the user’s files, sessions and corporate applications without targeting a conventional browser installation directly.
The fix was distributed months before the public exploitation report, but automatic update assumptions are not evidence of installation. Devices that were offline, unmanaged, cloned from old images or using uncontrolled software distribution may remain vulnerable. More importantly, installing the update does not remove an implant established before remediation. The enterprise decision is therefore to combine version discovery with endpoint hunting, containment and credential review rather than recording the vendor’s April release date as closure.
The decision for security leaders
Make regional IT and endpoint-security teams jointly accountable for finding the software. Central software inventories may omit language tools installed by users, included in regional images or present on contractor devices. Discovery should combine endpoint inventory, file and registry searches, software-distribution records and user outreach, with an explicit exception process for devices that cannot be inspected promptly.
Use a two-stage response. First, verify the patched version or remove Sogou where it is unnecessary. Second, hunt for the published malware, infrastructure and staging evidence across the period covered by retained telemetry. Any match should be treated as an endpoint compromise requiring isolation, forensic collection, rebuild and review of credentials and sessions available to the logged-in user.
Evidence of closure
- Endpoint inventory identifies every Sogou installation and validated version.
- IOC searches have preserved results and approved dispositions.
- Matched endpoints are rebuilt from trusted media.
- Credential and session resets cover users of confirmed compromised devices.
The Security.io assessment
The public disclosure is older than the primary publication window, but it materially changes an April software-update issue by establishing observed exploitation, naming the delivered implant and publishing huntable artefacts. That creates an enterprise action even for organisations that assumed automatic updating had resolved the problem. The highest exposure is in Asia-Pacific operations and among Chinese-language users whose endpoint software may not be governed by central standards.
Confidence in the technical chain is supported by detailed vendor research and independent reporting, but campaign scope and attribution remain constrained. No victim count, complete operational window or government attribution has been published. The embedded browser’s outdated architecture also remains a risk-management concern, but the cited evidence supports the specific reported chain rather than a conclusion that every residual embedded-browser weakness is currently exploited.
Questions for the morning meeting
- Where is Sogou Input Method installed across corporate, regional, contractor and travel-managed Windows devices?
- Can endpoint teams hunt the published hashes, domains, IP address and staging path?
- Which devices used a pre-16.3.0.3498 build before the automatic update was verified?