Gen Digital has published research on a China-linked intrusion in which the group tracked as UNC3569 โ placed by Google Threat Intelligence in China's hacker-for-hire scene and tracked by Google since 2021 as a threat to government, education, technology and finance sectors, mostly in East and Southeast Asia โ exploited a vulnerability in Sogou Input Method to install the GRAYRABBIT backdoor. Sogou Input Method is one of the most widely used tools for typing Chinese characters on Windows, which gives any exploit in it an extremely broad potential victim base, and Tencent, which owns and develops Sogou, fixed the flaw in April 2026. The attack chain started with a crafted link and ended with the attacker able to do anything the logged-in user could, via a small backdoor the group has used for years and which Google describes as its first step onto a machine. Gen Digital found the flaw while investigating a live intrusion rather than through proactive vulnerability research, meaning the exposure window between fix and discovery of exploitation was measured in months.
| Attribute | Detail |
|---|---|
| Sector | Defence |
| Date | 2026-09-12 |
| Source | The Hacker News |
| Reliability | Tier 2 |