ZeroHour
Story · 2 sources · 2 articlesfirst updated ()1

UNC3569 exploits one-click RCE in Tencent Sogou Input Method (CVE-2026-51990) to deploy GrayRabbit backdoor

criticalExploit / PoCexploited in the wildimportance 80CVE-2026-51990
What's new: First merged summary for this story, so there is no prior version to compare. The two reports (BleepingComputer, Sept 13; SecurityWeek, Sept 14) are consistent on the core facts: active in-the-wild exploitation of CVE-2026-51990 by UNC3569 and the patch in version 16.3.0.3498. SecurityWeek adds details: a possible link between UNC3569 and contractor i-SOON, that GrayRabbit has featured in UNC3569…
Merged summary · glm-5.3 · rewritten as coverage arrives

China-linked UNC3569 is actively exploiting CVE-2026-51990, a one-click RCE chain in Tencent Sogou Input Method for Windows, to install the GrayRabbit backdoor; Tencent patched the flaw in version 16.3.0.3498, but the outdated, unsandboxed Chromium 80 engine…

Gen Digital (Gen Threat Labs) reports that China-linked threat actor UNC3569 — which SecurityWeek says may be tied to the contractor-for-hire firm i-SOON — is actively exploiting CVE-2026-51990, a one-click, system-level remote code execution flaw in Tencent's Sogou Input Method for Windows, an IME with hundreds of millions of installations in China. The chain abuses unvalidated command-line argument injection via the sgbiz: URI handler, unrestricted URL navigation in a CEF-based webview, and an unsandboxed, outdated Chromium 80 engine missing roughly six years of security patches. Successful exploitation deploys the GrayRabbit backdoor, a mature 64-bit variant with an RC4-encoded C2 configuration that supports reverse shells, file transfer and upload to C2, system info collection, and reflective plugin loading; GrayRabbit has appeared in UNC3569 intrusions since at least 2021. Tencent patched the argument/URL validation issue in version 16.3.0.3498, delivered via automatic update, but the outdated, unsandboxed Chromium engine configuration reportedly remained unchanged as of September 10.

  • CVE-2026-51990 in Tencent Sogou Input Method for Windows is actively exploited in the wild by China-linked UNC3569, possibly tied to contractor i-SOON (per SecurityWeek)
  • Exploit chain combines unvalidated command-line argument injection via the sgbiz: URI handler, unrestricted URL navigation in a CEF-based webview, and an unsandboxed Chromium 80 engine missing roughly six years of security patches
  • The flaw yields one-click, system-level code execution; Sogou Input Method has hundreds of millions of installations in China
  • GrayRabbit backdoor: mature 64-bit variant with RC4-encoded C2 config providing reverse shells, file transfer/upload to C2, system info collection, and reflective plugin loading; used in UNC3569 intrusions since at least 2021
  • Tencent patched the issue in version 16.3.0.3498 via automatic update, adding URL/argument validation
  • The outdated, unsandboxed Chromium engine configuration reportedly remained unchanged as of September 10
  • Findings reported by Gen Digital / Gen Threat Labs; no material disagreements between the two sources

Coverage timeline

  1. · 2d ago
    BleepingComputer· 80
    Hackers exploit Tencent app flaw to deploy GrayRabbit malware

    UNC3569 actively exploits one-click RCE in Tencent Sogou Input Method to deploy the GrayRabbit backdoor, patched in version 16.3.0.3498.

  2. · 1d ago
    SecurityWeek· 80
    Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

    China-linked UNC3569 actively exploited critical Sogou Input Method flaw CVE-2026-51990 for one-click system-level code execution, deploying the GrayRabbit backdoor.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-51990

NVD description · AI analysis pending
PoC