Attackers exploited Sogou Input Method on Windows to install GrayRabbit, according to Gen Digital research covered by BleepingComputer on September 13, 2026. Gen identified the flaw as CVE-2026-51990 and attributed the intrusion to UNC3569. [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/).

Google researchers previously placed UNC3569 in China's cybercrime and contractor-for-hire ecosystem. Their 2024 study described operations targeting government, education, technology and finance, concentrated in East and Southeast Asia but extending elsewhere. These historical targets do not establish the victims of the Sogou intrusion. [Google research](https://www.virusbulletin.com/uploads/pdf/conference/vb2024/papers/Down-the-GRAYRABBIT-hole-exposing-UNC3569-and-its-modus-operandi.pdf).

Gen's September 10 analysis describes a crafted link passing unchecked arguments through Sogou's protocol handler. It directs an embedded browser to an attacker-controlled page, exploiting an outdated Chromium engine without sandbox protection.

Gen says the resulting code runs with the current user's privileges. The deployed backdoor supports remote commands, file transfers and additional plugins loaded into memory.

According to Gen, Tencent deployed the fix in version 16.3.0.3498 on April 21. It restricts destinations and requires HTTPS, blocking the observed entry route. Tencent said exploitation requires users to authorize a browser prompt.

Gen recommends updating to the latest Sogou version. Its analysis warns that the embedded browser remains outdated and unsandboxed despite the entry-point fix. [Gen Threat Labs](https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou).