A China‑linked threat group known as UNC3569 exploited a flaw in Sogou Input Method for Windows to deploy a backdoor, GRAYRABBIT, on victims’ machines. The attack began with a crafted link issued via email or chat that instructed Sogou’s settings program to launch a browser window inside Sogou’s Chromium-based component. The browser code had sandboxing and same‑origin policy protections disabled, allowing a JavaScript flaw on a malicious page to run with the user’s privileges.
The vulnerability chain culminated in an exploit for CVE-2021-38003, a Chrome V8 bug related to JSON[.]stringify, which could corrupt memory and execute code. Google tracked the issue as a long‑standing exploitation surface, with Sogou’s Windows build not receiving the relevant fixes. The attackers obtained a small downloader that fetched three files from an Alibaba Cloud server, including a DLL loader, an encrypted payload, and a final GRAYRABBIT payload. GRAYRABBIT provides a remote command shell, file exfiltration/movement, and the ability to load extra modules.
Tencent fixed the flaw in April 2026 via an automatic update to version 16.3.0.3498, but Gen Digital notes the fix did not alter the underlying browser engine (Cr Chromium 80, circa 2020) or many of the component settings. The GRAYRABBIT backdoor communicated with a command server at mail.uaiubifas[.]top on port 443 using non‑TLS RC4 traffic, and the loader left behind indicators such as specific SHA‑256 hashes, domain names, and an Alibaba Cloud staging IP (8.218.50[.]207).
Affected users are advised to update Sogou Input Method to 16.3.0.3498 and review indicators: SHA‑256 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 (malicious DLL loader, named 7z[.]dll), SHA‑256 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e (encrypted payload, named p), SHA‑256 d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a (GRAYRABBIT, core[.]dll). Portents include the noht1ng[.]top exploit host and the staging IP 8.218.50[.]207.