# Gen Digital ties China-linked UNC3569 to Sogou input flaw used to plant GRAYRABBIT backdoor

_Friday, September 11, 2026 at 3:14 AM EDT · Security · Latest · Tier 2 — Notable_

![Gen Digital ties China-linked UNC3569 to Sogou input flaw used to plant GRAYRABBIT backdoor — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjp8vDxYtUGwWuRZlSSBh2ghvSf6GTi_VlTQSQXTaIWSlQgHY_imEfl4hyAcrhPz9w3_ejmdAKK7ZeOt5gBsNZI7mhxJsnbyLT8Bo6O6HdM01yCNuDjuz-IU64LRuAuVDOzh2Z0vLhvzwP9PUUBKE_OLn0YD7m74-kZpo1dr5c0hzCMRHxrgfIzjk9MnR4/s1700-nu-rw-lo-l85-e365/chinese.jpg)

Gen Digital said a China-linked group it calls UNC3569 exploited a flaw in Tencent's Sogou Input Method for Windows to install the GRAYRABBIT backdoor, which gives attackers a remote command shell and can load additional modules.

Gen reported the flaw to Tencent on April 9, 2026, and Tencent confirmed a fix that went out by automatic update on April 21, tracked as CVE-2026-51990. The fix hardens the link handler that launched Sogou components, but Gen found the bundled Chromium engine and its disabled sandbox unchanged.

Tencent disputed the chain's simplicity, saying social engineering would be needed.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html)

---
Canonical: https://techandbusiness.org/newswire/ksA0DvA_q0fDxsAR_OuuSv
Retrieved: 2026-09-12T04:09:38.551Z
Publisher: Tech & Business (techandbusiness.org)
