China-Linked UNC3569 Chained Sogou Input Method One-Click RCE (CVE-2026-51990) with Old V8 Bug to Deploy GRAYRABBIT Backdoor
Gen Digital found China-linked UNC3569 exploiting a one-click RCE in Tencent's Sogou Input Method for Windows (CVE-2026-51990), chaining it with 2021's CVE-2021-38003 to deploy the GRAYRABBIT espionage backdoor against targets across East and Southeast Asia.
Gen Digital (Gen Threat Labs) reported that UNC3569, a China-linked / PRC-nexus hacker-for-hire espionage actor tracked by Google since 2021, exploited CVE-2026-51990, a one-click remote code execution flaw in Sogou Input Method for Windows that runs with the signed-in user's permissions. The flaw comprises three weaknesses in the sgbiz: protocol handler that chain into the RCE, abusing the handler to reach a sandbox-disabled Chromium 80 CEF webview embedded in the app. The attackers then weaponized CVE-2021-38003, a 2021 V8 type confusion, to execute shellcode — possible because the embedded browser never received the 2021 V8 fixes. The payload is delivered via DLL sideloading using 7z.exe with a malicious 7z.dll, which decrypts only when 50+ processes are running, an anti-analysis check. The final implant, GRAYRABBIT, is a remote shell backdoor supporting file transfer and module loading, and beacons to mail.uaiubifas[.]top over RC4-encrypted raw TCP port 443. Targets span the government, education, technology, and financial sectors across East and Southeast Asia. Tencent patched the handler flaw in version 16.3.0.3498, released via automatic updates on April 21, 2026 — within 12 days of disclosure — but the embedded Chromium 80 browser remains outdated and unpatched. Sogou Input Method has over 455 million monthly users and roughly 70% share of the Chinese input method market, leaving the stale embedded browser a lingering concern. All three reports agree on the core facts; the GBHackers and Cyber Security News accounts add the CVE-2026-51990 identifier, patch version, and timeline details absent from the earlier Hacker News report.
- Actor: UNC3569, China-linked / PRC-nexus hacker-for-hire espionage group tracked by Google since 2021
- CVE-2026-51990: one-click RCE in Sogou Input Method for Windows, running with the signed-in user's permissions, built from three weaknesses in the sgbiz: protocol handler
- Exploit chain reaches a sandbox-disabled Chromium 80 CEF webview and reuses CVE-2021-38003, a 2021 V8 type confusion, for shellcode execution
- GRAYRABBIT backdoor delivered via 7-Zip DLL sideloading (7z.exe + malicious 7z.dll); payload decrypts only when 50+ processes are running (anti-analysis)
- GRAYRABBIT capabilities: remote shell, file transfer, module loading; C2 at mail.uaiubifas[.]top over RC4-encrypted raw TCP port 443
- Targets: government, education, technology, and financial sectors across East and Southeast Asia
- Tencent patched the handler flaw in Sogou Input Method 16.3.0.3498, released via automatic updates on April 21, 2026, within 12 days of disclosure; the embedded Chromium 80 browser remains unpatched
- Sogou Input Method has over 455 million monthly users and roughly 70% of the Chinese input method market
Coverage timelineoldest first · each row is one article
- · 4d agoChina-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
The Hacker News· 74
China-linked UNC3569 exploited a Sogou Input Method flaw to deploy GRAYRABBIT backdoor on Windows machines across East and Southeast Asia.
- · 1d agoChina-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor
GBHackers· 82
China-linked UNC3569 exploited CVE-2026-51990 in Sogou Input Method to deploy the GRAYRABBIT backdoor in active espionage intrusions.
- · 1d agoOne Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users
Cyber Security News· 78
Actively exploited one-click flaw in Sogou Input Method (CVE-2026-51990) let UNC3569 deploy the GRAYRABBIT espionage backdoor on Windows.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-38003 | Memory Corruption in Chromium V8 JSON.stringify Affects Chrome, Edge, Opera CVE-2021-38003 is a memory corruption flaw in the V8 JavaScript engine used by Chromium, in which the engine's internal 'TheHole' sentinel value can leak into script-visible data during JSON.stringify processing (a heap-corruption condition tracked as CWE-122 and CWE-755). It is triggered when crafted JavaScript causes JSON.stringify to expose this internal value to script code. An attacker who can induce a victim to load malicious web content can leverage the resulting corruption, typically chained with further techniques, to execute code within the browser renderer or crash it. All users of Chromium-based browsers — explicitly including Google Chrome, Microsoft Edge, and Opera, and by extension other Chromium derivatives — are affected. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03, carries a 38.6% EPSS probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known. Do: Update all Chromium-based browsers (Chrome, Edge, Opera, and any Chromium-embedded or Electron-style applications in your estate) to the latest vendor-patched releases, per the CISA KEV required action to apply updates per vendor instructions. Verify remediated browser versions via enterprise update management and browser version reporting, prioritizing user workstations and externally reachable systems. Because exploitation is confirmed in the wild, treat unpatched Chromium browsers as an active exposure rather than a theoretical risk. | 8.8 | 39% | KEV PoC |
| mass≈3 billion users (combined Chromium-based browser install base, Chrome alone accounting for the large majority) | |
| CVE-2026-51990 | NVD description · AI analysis pending | — | — | PoC | — | — | — |