Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
China-Linked Hackers Exploit Sogou Flaw for Backdoor

China-Linked Hackers Exploit Sogou Flaw for Backdoor

Posted on September 11, 2026 By CWS

A China-linked cyber group, identified as UNC3569, exploited a vulnerability in the Sogou Input Method on Windows to deploy a backdoor on target systems, according to a report by Gen Digital. The Sogou Input Method is a widely used tool for typing Chinese characters, and the flaw was patched by Tencent in April 2026.

Exploitation of Sogou Input Method

The cyber attack commenced with a specially crafted link that allowed attackers to execute commands as the logged-in user. Gen Digital discovered the vulnerability during an investigation of an active breach by UNC3569, a group linked to China and tracked by Google Threat Intelligence since 2021. The attackers primarily targeted sectors such as government, education, technology, and finance, primarily in East and Southeast Asia.

Through this exploit, the attackers installed the GRAYRABBIT backdoor, a long-used tool providing remote command shell capabilities and enabling file transfers. Despite Tencent’s security patch, the underlying cause of the attack remains unaddressed, with the built-in browser engine still running an outdated version of Chromium from 2020.

Mechanism of the Attack

Sogou Input Method’s popularity, with over 455 million monthly users across different platforms according to 2023 research, made it an attractive target. The flaw was found in the Windows version, where components communicate via a custom link type registered as sgbiz:. This oversight allowed attackers to craft links that directed the Sogou settings program to open a browser at a malicious address.

The outdated browser, using Chromium version 80, had its security sandbox disabled. This allowed JavaScript vulnerabilities to be exploited, facilitating code execution with user privileges. Although Tencent described the attack chain as complex, requiring user interaction, Gen Digital asserts that the exploit could still succeed through social engineering.

Vulnerability Details and Countermeasures

The attackers leveraged a 2021 browser vulnerability, CVE-2021-38003, which compromised the V8 JavaScript engine’s handling of JSON.stringify. Despite being fixed in Chrome 95, Sogou’s browser never received this update, leaving it susceptible. Gen Digital’s investigation highlighted that many security updates were missing from the Sogou build.

The attack involved deploying a downloader which retrieved additional malicious files from a server in Hong Kong. The payload included a legitimate 7-Zip copy, a malicious DLL, and an encrypted file. Once executed, the malicious DLL evaded detection by deleting itself and hiding traces in NTFS alternate data streams.

Tencent responded by updating the biz_helper.exe component to restrict web addresses to trusted domains. However, the core browser engine remains unchanged, highlighting the need for further security enhancements.

Recommendations and Future Outlook

Users are advised to update their Sogou Input Method to version 16.3.0.3498, released on April 21, 2026, to mitigate the risk. While the patch addresses the immediate vulnerability, the outdated browser engine poses ongoing risks. Comprehensive updates to the browser component are necessary for enhanced security.

For systems potentially compromised prior to the update, users should check for specific indicators published by Gen Digital. These include traces of the malicious loader and backdoor. As cyber threats evolve, proactive security measures and timely updates remain crucial to safeguarding systems against sophisticated attacks.

The Hacker News Tags:Alibaba Cloud, China hackers, Chromium, CISA vulnerabilities, CVE-2021-38003, cyber attack, Cybersecurity, Google Threat Intelligence, GRAYRABBIT backdoor, Malware, sandbox vulnerability, security flaw, Sogou Input Method, Tencent, UNC3569

Post navigation

Previous Post: Hackers Hide AI Threats in Plain English, Evade Security
Next Post: Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Related Posts

North Korean Hackers Exploit AI for Enhanced Cyber Attacks North Korean Hackers Exploit AI for Enhanced Cyber Attacks The Hacker News
Executives Targeted in Microsoft 365 Data Extortion Scam Executives Targeted in Microsoft 365 Data Extortion Scam The Hacker News
Anthropic Disrupts AI-Powered Cyberattacks Automating Theft and Extortion Across Critical Sectors Anthropic Disrupts AI-Powered Cyberattacks Automating Theft and Extortion Across Critical Sectors The Hacker News
Google’s Quantum-Resistant HTTPS Initiative in Chrome Google’s Quantum-Resistant HTTPS Initiative in Chrome The Hacker News
Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances The Hacker News
Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities
  • Surfshark Security Breach: No User Data Compromised
  • PaperCut Issues New Security Updates for Critical Flaws
  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities
  • Surfshark Security Breach: No User Data Compromised
  • PaperCut Issues New Security Updates for Critical Flaws
  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark