Tencent Patches Critical Flaw in Sogou Input Method After GrayRabbit Attacks

A China-linked espionage group known as UNC3569 has been observed exploiting a vulnerability in Tencent’s Sogou Input Method for Windows to deploy a persistent backdoor. The attack chain allows for remote code execution by leveraging a legacy browser engine embedded within the popular Chinese-language typing software, which currently maintains an estimated 455 million monthly active users.

The campaign results in the installation of the GrayRabbit backdoor, a sophisticated piece of malware that provides attackers with deep access to compromised systems. While Tencent released a patch for the primary vulnerability in April 2026, security researchers note that the software’s underlying architecture continues to present significant risks to its global user base.

Technical concept of an unsandboxed browser engine inside a software application.
Sogou’s use of an unsandboxed Chromium engine created a gateway for the backdoor.

The Anatomy of a ‘One-Click’ Hijack

The exploitation of Sogou Input Method is technically significant because it bypasses modern security protections by targeting a neglected component of the application. The software relies on a heavily outdated version of Chromium—specifically version 80, which dates back to 2020—to render certain internal interfaces. This browser engine is notably integrated without a security sandbox and with the Same-Origin Policy (SOP) disabled, leaving it highly vulnerable to web-based attacks.

Security analysis indicates that the threat actors successfully weaponized CVE-2021-38003, a vulnerability in the Chromium V8 engine that was patched by Google in late 2021. Because Sogou continued to ship with the unpatched 2020 engine, UNC3569 was able to use the flaw years after its public disclosure to gain control over Windows PCs when users interacted with malicious links or commands triggered through the app.

The use of an unsandboxed browser engine means that once the V8 engine is compromised, the attacker’s code runs with the same permissions as the Sogou application itself. In many Windows environments, this allows for immediate system-level influence without requiring the further privilege escalation steps typically needed in modern browser exploits.

Response and Persistent Risks

Tencent addressed the immediate vulnerability in Sogou Input Method version 16.3.0.3498, which was released on April 21, 2026. Users are urged to verify they are running this version or a later iteration to mitigate the specific “one-click” exploit used to deliver GrayRabbit. However, the architectural reliance on a legacy, unsandboxed Chromium engine remains a point of concern for security analysts.

The GrayRabbit backdoor deployed in these attacks is a multi-stage malware capable of file exfiltration, keystroke logging, and further payload delivery. Because the Sogou software is a critical productivity tool for millions of users, particularly within Chinese-speaking regions and international business hubs, it represents a high-value target for state-aligned actors seeking long-term persistence on corporate and personal devices.

To secure systems against this and similar threats, administrators are advised to:

  • Update Sogou Input Method to version 16.3.0.3498 or newer immediately.
  • Monitor for unusual outbound traffic associated with the GrayRabbit command-and-control infrastructure.
  • Consider the risks of using third-party input method editors (IMEs) that integrate web-rendering engines without modern sandboxing protocols.

The timeline of this incident highlights a growing trend in cybersecurity: the weaponization of “forgotten” components within trusted applications. While high-profile browsers like Chrome and Edge are patched within days of a vulnerability discovery, the embedded versions of those same engines inside desktop utilities often remain vulnerable for years, providing a silent gateway for targeted espionage.

More From Category

More Stories Today