Key Facts
Gen Threat Labs reports that UNC3569 actively exploited a one-click attack chain in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor.
Technical Details
Gen says the chain abuses the sgbiz: protocol handler, unrestricted webview navigation, and an outdated unsandboxed Chromium engine. BleepingComputer reports that the crafted-link attack can result in remote code execution after a user click.
Impact & Mitigation
Gen says Tencent released Sogou Input Method 16.3.0.3498 with protocol-handler restrictions. Update to the fixed version and investigate affected endpoints for GrayRabbit or suspicious protocol-handler activity.
