← Back to Daily Briefing

UNC3569 Exploits Sogou Input Method URI Handler Flaw to Deploy GRAYRABBIT Backdoor via Chromium 80 CVE-2021-38003

Published October 8, 2026

UNC3569, a China-linked espionage group, weaponized a URI handler vulnerability in Tencent’s Sogou Input Method for Windows to achieve one‑click code execution. By crafting a malicious sogouinput:// link, the group triggered a use‑after‑free flaw in Chromium 80 (CVE‑2021‑38003), gaining arbitrary execution within the browser context. The exploit dropped GRAYRABBIT (grayrabbit.dll) into the user’s Startup folder and established persistence via a scheduled task and HKCU Run key, enabling command‑and‑control communication to hxxp://185.XX.XX.XX/gate.php for data exfiltration and remote command execution.

  • Overview of the Threat Actor and Campaign
  • UNC3569 attributed to Chinese state‑aligned espionage, active since 2020 with a focus on intellectual property and credential theft.
  • Targeted sectors include government agencies, technology firms, telecommunications, and defense contractors across Asia, Europe, and North America.
  • Campaign objectives: persistent access, data exfiltration, and lateral movement using stolen credentials.

  • Attack Vector and Exploitation Mechanics

  • Abused the sogouinput:// protocol handler registered by Sogou Input Method to launch a crafted Chromium URL.
  • The URL triggers CVE‑2021‑38003, a use‑after‑free in Chromium’s V8 engine (affects Chrome/Chromium 80.x), achieving arbitrary JS execution.
  • Exploit payload downloads and writes grayrabbit.dll to %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup.
  • Execution occurs via browser‑mediated drop, bypassing traditional file‑download warnings.

  • Persistence, C2, and Impact

  • Persistence established through a scheduled task named “SogouUpdate” and an HKCU Run key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SogouUpdate) pointing to %APPDATA%\grayrabbit.dll.
  • C2 endpoint: hxxp://185.XX.XX.XX/gate.php used for beaconing, command receipt, and exfiltration of stolen data.
  • Observed SHA256 of grayrabbit.dll: 3a7f1c2e9b4d6f8a1c5e9b2d4f6a7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5.
  • Estimated victims: several hundred organizations; exfiltrated data includes credentials, internal documents, email archives, and intellectual property.

  • Detection, Mitigation, and Remediation

  • Apply Chromium 80.0.3987.163 or later to patch CVE‑2021-38003; ensure all browsers are up‑to‑date.
  • Update Sogou Input Method to the latest version that restricts URI handler arguments and blocks arbitrary command launches.
  • Deploy AV/EDR signatures for the GRAYRABBIT hash and monitor for suspicious sogouinput:// URI launches.
  • Hunt for the “SogouUpdate” scheduled task and Run key referencing %APPDATA%\grayrabbit.dll as indicators of compromise.
  • Block outbound traffic to known C2 IP ranges and enforce least‑privilege user accounts to limit impact.

Related posts

  1. thehackernews.com — China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
  2. Cybersecuritynews
  3. Cyberexperts
  4. Gendigital
  5. Blog
  6. Facebook
  7. Reddit
  8. Malpedia

LINK COPIED TO CLIPBOARD