China-linked threat actor UNC3569 actively exploited critical remote-code-execution flaw CVE-2026-51990 in Tencent Sogou Input Method for Windows to install the GRAYRABBIT backdoor. Victims could be compromised through a crafted sgbiz: link that injected attacker-controlled arguments, opened Sogou's Skin Center CEF webview at a malicious site, and exploited the Chromium V8 vulnerability CVE-2021-38003 to execute code in the logged-in user's context.
Tencent released Sogou Input Method version 16.3.0.3498 through automatic updates, adding validation for URL-bearing protocol-handler arguments. However, researchers reported that the application continues to embed Chromium 80 with its sandbox and web-security/same-origin protections disabled. GRAYRABBIT used 7-Zip DLL sideloading, anti-analysis and self-deletion measures, and RC4-obfuscated non-TLS command-and-control traffic over TCP port 443.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
As of September 10, 2026, Sogou Input Method reportedly still used the outdated Chromium 80 component with its sandbox disabled and key web protections removed. Tencent's version 16.3.0.3498 update fixed the protocol-handler issue but reportedly did not update the underlying Chromium version or configuration.
MITRE assigned identifier CVE-2026-51990 to the critical Sogou Input Method remote-code-execution vulnerability chain.
Tencent deployed an automatic-update fix in Sogou Input Method version 16.3.0.3498. The patch added HTTPS and hostname-suffix allowlisting for URL-bearing arguments handled by biz_helper.exe.
Tencent acknowledged Gen Threat Labs' vulnerability report concerning the Sogou Input Method flaw.
Gen Threat Labs reported the critical Sogou Input Method remote-code-execution chain to Tencent.
CISA added the Chrome V8 vulnerability CVE-2021-38003 to its Known Exploited Vulnerabilities Catalog.
Google patched the V8 type-confusion vulnerability CVE-2021-38003 in Chrome 95. Sogou Input Method's embedded Chromium 80 component did not receive this fix.
PRC-linked UNC3569 actively exploited the Sogou Input Method vulnerability later assigned CVE-2026-51990. Crafted sgbiz: links opened an attacker-controlled page in Sogou's insecure Chromium 80 webview, which exploited CVE-2021-38003 to deliver the GRAYRABBIT backdoor through 7-Zip DLL sideloading.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcesecurityweek.com
Open sourcecysecurity.news
Open sourcethehackernews.com
Open sourcegendigital.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.