Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
China-Linked Hackers Exploit Sogou Flaw for Backdoor

China-Linked Hackers Exploit Sogou Flaw for Backdoor

Posted on September 11, 2026 By CWS

A China-linked cyber group, identified as UNC3569, exploited a vulnerability in the Sogou Input Method on Windows to deploy a backdoor on target systems, according to a report by Gen Digital. The Sogou Input Method is a widely used tool for typing Chinese characters, and the flaw was patched by Tencent in April 2026.

Exploitation of Sogou Input Method

The cyber attack commenced with a specially crafted link that allowed attackers to execute commands as the logged-in user. Gen Digital discovered the vulnerability during an investigation of an active breach by UNC3569, a group linked to China and tracked by Google Threat Intelligence since 2021. The attackers primarily targeted sectors such as government, education, technology, and finance, primarily in East and Southeast Asia.

Through this exploit, the attackers installed the GRAYRABBIT backdoor, a long-used tool providing remote command shell capabilities and enabling file transfers. Despite Tencent’s security patch, the underlying cause of the attack remains unaddressed, with the built-in browser engine still running an outdated version of Chromium from 2020.

Mechanism of the Attack

Sogou Input Method’s popularity, with over 455 million monthly users across different platforms according to 2023 research, made it an attractive target. The flaw was found in the Windows version, where components communicate via a custom link type registered as sgbiz:. This oversight allowed attackers to craft links that directed the Sogou settings program to open a browser at a malicious address.

The outdated browser, using Chromium version 80, had its security sandbox disabled. This allowed JavaScript vulnerabilities to be exploited, facilitating code execution with user privileges. Although Tencent described the attack chain as complex, requiring user interaction, Gen Digital asserts that the exploit could still succeed through social engineering.

Vulnerability Details and Countermeasures

The attackers leveraged a 2021 browser vulnerability, CVE-2021-38003, which compromised the V8 JavaScript engine’s handling of JSON.stringify. Despite being fixed in Chrome 95, Sogou’s browser never received this update, leaving it susceptible. Gen Digital’s investigation highlighted that many security updates were missing from the Sogou build.

The attack involved deploying a downloader which retrieved additional malicious files from a server in Hong Kong. The payload included a legitimate 7-Zip copy, a malicious DLL, and an encrypted file. Once executed, the malicious DLL evaded detection by deleting itself and hiding traces in NTFS alternate data streams.

Tencent responded by updating the biz_helper.exe component to restrict web addresses to trusted domains. However, the core browser engine remains unchanged, highlighting the need for further security enhancements.

Recommendations and Future Outlook

Users are advised to update their Sogou Input Method to version 16.3.0.3498, released on April 21, 2026, to mitigate the risk. While the patch addresses the immediate vulnerability, the outdated browser engine poses ongoing risks. Comprehensive updates to the browser component are necessary for enhanced security.

For systems potentially compromised prior to the update, users should check for specific indicators published by Gen Digital. These include traces of the malicious loader and backdoor. As cyber threats evolve, proactive security measures and timely updates remain crucial to safeguarding systems against sophisticated attacks.

The Hacker News Tags:Alibaba Cloud, China hackers, Chromium, CISA vulnerabilities, CVE-2021-38003, cyber attack, Cybersecurity, Google Threat Intelligence, GRAYRABBIT backdoor, Malware, sandbox vulnerability, security flaw, Sogou Input Method, Tencent, UNC3569

Post navigation

Previous Post: Hackers Hide AI Threats in Plain English, Evade Security
Next Post: Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Related Posts

Microsoft Patches 130 Vulnerabilities, Including Critical Flaws in SPNEGO and SQL Server Microsoft Patches 130 Vulnerabilities, Including Critical Flaws in SPNEGO and SQL Server The Hacker News
Why IT Leaders Must Rethink Backup in the Age of Ransomware Why IT Leaders Must Rethink Backup in the Age of Ransomware The Hacker News
Salesloft OAuth Breach via Drift AI Chat Agent Exposes Salesforce Customer Data Salesloft OAuth Breach via Drift AI Chat Agent Exposes Salesforce Customer Data The Hacker News
Critical Vulnerabilities in FreeIPA Allow Unauthorized Access Critical Vulnerabilities in FreeIPA Allow Unauthorized Access The Hacker News
Severe Bugs in AI Code Editor Risk System Intrusion Severe Bugs in AI Code Editor Risk System Intrusion The Hacker News
How One Bad Password Ended a 158-Year-Old Business How One Bad Password Ended a 158-Year-Old Business The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic
  • China-Linked Hackers Exploit Sogou Flaw for Backdoor
  • Hackers Hide AI Threats in Plain English, Evade Security
  • Exploits Target JFrog Artifactory Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic
  • China-Linked Hackers Exploit Sogou Flaw for Backdoor
  • Hackers Hide AI Threats in Plain English, Evade Security
  • Exploits Target JFrog Artifactory Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark