Key Facts

Gen Threat Labs reports that UNC3569 actively exploited a one-click attack chain in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor.

Technical Details

Gen says the chain abuses the sgbiz: protocol handler, unrestricted webview navigation, and an outdated unsandboxed Chromium engine. BleepingComputer reports that the crafted-link attack can result in remote code execution after a user click.

Impact & Mitigation

Gen says Tencent released Sogou Input Method 16.3.0.3498 with protocol-handler restrictions. Update to the fixed version and investigate affected endpoints for GrayRabbit or suspicious protocol-handler activity.

Sources

By Allan