techjacksolutions.com • 3h
UNC3569 Exploits Sogou Input Method URI Handler Flaw to Deploy GRAYRABBIT Backdoor via Chromium 80 CVE-2021-38003
UNC3569, a China-linked espionage group, weaponized a URI handler vulnerability in Tencent’s Sogou Input Method for Windows to achieve one‑click code execution. By crafting a malicious sogouinput:// link, the group triggered a use‑after‑free flaw in Chromium 80 (CVE‑2021‑38003), gaining arbitrary execution within the browser context. The exploit dropped GRAYRABBIT (grayrabbit.dll) into the user’s Startup folder and established persistence via a scheduled task and HKCU Run key, enabling command‑and‑control communication to hxxp://185.XX.XX.XX/gate.php for data exfiltration and remote command execution.