← Back to Daily Briefing (Tencent (Sogou Input Method))

UNC3569 Exploits Sogou Input Method URI Handler Flaw to Deploy GRAYRABBIT Backdoor via Chromium 80 CVE-2021-38003

Published October 8, 2026

UNC3569, a China-linked espionage group, weaponized a URI handler vulnerability in Tencent’s Sogou Input Method for Windows to achieve one‑click code execution. By crafting a malicious sogouinput:// link, the group triggered a use‑after‑free flaw in Chromium 80 (CVE‑2021‑38003), gaining arbitrary execution within the browser context. The exploit dropped GRAYRABBIT (grayrabbit.dll) into the user’s Startup folder and established persistence via a scheduled task and HKCU Run key, enabling command‑and‑control communication to hxxp://185.XX.XX.XX/gate.php for data exfiltration and remote command execution.

  • Overview of the Threat Actor and Campaign
  • UNC3569 attributed to Chinese state‑aligned espionage, active since 2020 with a focus on intellectual property and credential theft.
  • Targeted sectors include government agencies, technology firms, telecommunications, and defense contractors across Asia, Europe, and North America.
  • Campaign objectives: persistent access, data exfiltration, and lateral movement using stolen credentials.

  • Attack Vector and Exploitation Mechanics

  • Abused the sogouinput:// protocol handler registered by Sogou Input Method to launch a crafted Chromium URL.
  • The URL triggers CVE‑2021‑38003, a use‑after‑free in Chromium’s V8 engine (affects Chrome/Chromium 80.x), achieving arbitrary JS execution.
  • Exploit payload downloads and writes grayrabbit.dll to %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup.
  • Execution occurs via browser‑mediated drop, bypassing traditional file‑download warnings.

  • Persistence, C2, and Impact

  • Persistence established through a scheduled task named “SogouUpdate” and an HKCU Run key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SogouUpdate) pointing to %APPDATA%\grayrabbit.dll.
  • C2 endpoint: hxxp://185.XX.XX.XX/gate.php used for beaconing, command receipt, and exfiltration of stolen data.
  • Observed SHA256 of grayrabbit.dll: 3a7f1c2e9b4d6f8a1c5e9b2d4f6a7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5.
  • Estimated victims: several hundred organizations; exfiltrated data includes credentials, internal documents, email archives, and intellectual property.

  • Detection, Mitigation, and Remediation

  • Apply Chromium 80.0.3987.163 or later to patch CVE‑2021-38003; ensure all browsers are up‑to‑date.
  • Update Sogou Input Method to the latest version that restricts URI handler arguments and blocks arbitrary command launches.
  • Deploy AV/EDR signatures for the GRAYRABBIT hash and monitor for suspicious sogouinput:// URI launches.
  • Hunt for the “SogouUpdate” scheduled task and Run key referencing %APPDATA%\grayrabbit.dll as indicators of compromise.
  • Block outbound traffic to known C2 IP ranges and enforce least‑privilege user accounts to limit impact.

Related posts

  1. techjacksolutions.com — UNC3569 Exploited Sogou Input Method URI Handler Flaw to Deploy GRAYRABBIT Backdoor via Chained Chromium 80 / CVE-2021-38003 Exploit
  2. thehackernews.com — China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
  3. Cybersecuritynews
  4. Cyberexperts
  5. Gendigital
  6. Isec
  7. Radar
  8. Cyberpresso
  9. Blog
  10. Facebook
  11. Reddit
  12. Malpedia

LINK COPIED TO CLIPBOARD