Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Threat actors linked to a China-aligned espionage group are exploiting critical vulnerability CVE-2026-51990 in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor, Gen Digital researchers report.

Gen Threat Labs says UNC3569 used a one-click remote code execution attack in the wild. The chain starts when a victim clicks a crafted sgbiz: link. Sogou’s biz_helper.exe handler passes attacker-controlled arguments to SGMyInput.exe, opening the skincenter component and loading an attacker-controlled URL in its embedded Chromium 80 webview.

The webview does not restrict URL schemes or destinations. A malicious page then exploits the outdated browser, which runs without a sandbox and with important web-security protections disabled. The attack installs GrayRabbit, a modular malware family linked to UNC3569 by Google researchers in 2024.

The analyzed sample is a more mature 64-bit variant with an expanded command set and RC4-encoded C2 configuration. It can execute processes, open interactive reverse shells, upload and download files, collect system and user information, and load plugins reflectively in memory.

Gen Threat Labs reported the findings to Tencent on April 9. Tencent released Sogou Input Method version 16.3.0.3498 on April 21. The fix validates protocol-handler URL arguments, permits only HTTPS, and limits navigation to approved Sogou and Tencent domains. Researchers warn that the underlying browser remains outdated and unsandboxed.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.