PT-2026-89805 · Undefined · Undefined
CVE-2026-51990
·
Published
2026-09-11
·
Updated
2026-09-12
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
🚨 CYBER ESPIONAGE — UNC3569 TURNED ONE SOGOU INPUT METHOD CLICK INTO A WINDOWS BACKDOOR
A custom URI handler + an outdated embedded Chromium environment ultimately enabled deployment of GRAYRABBIT.
CyberSignal Priority: 🔴 VERY HIGH
🇨🇳 UNC3569
⌨️ Sogou Input Method
CVE-2026-51990
🦠 GRAYRABBIT
🔎 What happened
Gen Digital documented a multi-stage exploitation chain affecting vulnerable Windows versions of Sogou Input Method.
The attack begins with Sogou's registered:
sgbiz:
custom protocol handler.
Attacker-controlled input could reach Sogou's CEF-based skin-center component and force it to load malicious content.
The dangerous part:
the embedded browser was based on Chromium 80, a 2020-era codebase, while important protections—including sandboxing—were disabled.
⚔️ Attack chain
Malicious link
↓
sgbiz: URI handler
↓
Sogou embedded Chromium
↓
Browser exploitation
↓
Native-code execution
↓
7-Zip DLL side-loading
↓
GRAYRABBIT backdoor
The downloader places a legitimate 7z executable beside a malicious DLL, causing execution through DLL side-loading.
GRAYRABBIT performs environmental checks designed to identify analysis systems and uses additional evasion techniques.
Its C2 communications use raw TCP over port 443 with RC4-based protection.
🎯 What is affected
Vulnerable Windows installations of Sogou Input Method.
🧠 Why this matters
Embedded browsers exist inside enormous numbers of desktop applications.
They may quietly inherit years of browser vulnerabilities while receiving far less security scrutiny than Chrome, Edge or Firefox.
⚠️ Important caveat
This is primarily a fresh exploitation/tradecraft disclosure, not an unfixed zero-day.
Tencent was notified earlier and Sogou 16.3.0.3498 contains the fix.
🛡️ Defender action
Upgrade Sogou.
Hunt for:
Sogou → browser/script execution
Sogou → 7z
DLL side-loading
raw TCP/443 without expected TLS
unusual child processes
CyberSignal insight: A browser does not stop being a browser attack surface because somebody hid it inside another application.
Sources: Gen Digital Threat Research · Tencent/Sogou coordinated disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined