UNC3569 exploits one-click RCE in Tencent Sogou Input Method (CVE-2026-51990) to deploy GrayRabbit backdoor
China-linked UNC3569 is actively exploiting CVE-2026-51990, a one-click RCE chain in Tencent Sogou Input Method for Windows, to install the GrayRabbit backdoor; Tencent patched the flaw in version 16.3.0.3498, but the outdated, unsandboxed Chromium 80 engine…
Gen Digital (Gen Threat Labs) reports that China-linked threat actor UNC3569 — which SecurityWeek says may be tied to the contractor-for-hire firm i-SOON — is actively exploiting CVE-2026-51990, a one-click, system-level remote code execution flaw in Tencent's Sogou Input Method for Windows, an IME with hundreds of millions of installations in China. The chain abuses unvalidated command-line argument injection via the sgbiz: URI handler, unrestricted URL navigation in a CEF-based webview, and an unsandboxed, outdated Chromium 80 engine missing roughly six years of security patches. Successful exploitation deploys the GrayRabbit backdoor, a mature 64-bit variant with an RC4-encoded C2 configuration that supports reverse shells, file transfer and upload to C2, system info collection, and reflective plugin loading; GrayRabbit has appeared in UNC3569 intrusions since at least 2021. Tencent patched the argument/URL validation issue in version 16.3.0.3498, delivered via automatic update, but the outdated, unsandboxed Chromium engine configuration reportedly remained unchanged as of September 10.
- CVE-2026-51990 in Tencent Sogou Input Method for Windows is actively exploited in the wild by China-linked UNC3569, possibly tied to contractor i-SOON (per SecurityWeek)
- Exploit chain combines unvalidated command-line argument injection via the sgbiz: URI handler, unrestricted URL navigation in a CEF-based webview, and an unsandboxed Chromium 80 engine missing roughly six years of security patches
- The flaw yields one-click, system-level code execution; Sogou Input Method has hundreds of millions of installations in China
- GrayRabbit backdoor: mature 64-bit variant with RC4-encoded C2 config providing reverse shells, file transfer/upload to C2, system info collection, and reflective plugin loading; used in UNC3569 intrusions since at least 2021
- Tencent patched the issue in version 16.3.0.3498 via automatic update, adding URL/argument validation
- The outdated, unsandboxed Chromium engine configuration reportedly remained unchanged as of September 10
- Findings reported by Gen Digital / Gen Threat Labs; no material disagreements between the two sources
Coverage timelineoldest first · each row is one article
- · 2d agoHackers exploit Tencent app flaw to deploy GrayRabbit malware
BleepingComputer· 80
UNC3569 actively exploits one-click RCE in Tencent Sogou Input Method to deploy the GrayRabbit backdoor, patched in version 16.3.0.3498.
- · 1d agoChinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
SecurityWeek· 80
China-linked UNC3569 actively exploited critical Sogou Input Method flaw CVE-2026-51990 for one-click system-level code execution, deploying the GrayRabbit backdoor.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-51990 | NVD description · AI analysis pending | — | — | PoC | — | — | — |