At a Glance
Security researchers at Gen Threat Labs discovered a critical remote code execution flaw in Sogou Input Method. This software serves as one of the most widely used typing tools in China. Tracked as CVE-2026-51990, the critical Sogou Input Method vulnerability allows remote attackers to install malicious programs with a single click. In fact, attackers actively exploited the Sogou Input Method vulnerability in wild attacks before developers patched the software.
Track every CVE that hits your stack the moment it's exploited.
Get free email alerts| Actor or Group | UNC3569 (Suspected China-nexus espionage group) |
|---|---|
| Activity Type | Remote code execution and backdoor deployment |
| Targets or Victims | Government, education, technology, and finance sectors |
| Scale | Hundreds of millions of installed desktop clients worldwide |
| Jurisdiction Status | No criminal charges filed; vendor patched the vulnerability after coordinated disclosure |
| Source | Gen Threat Labs and Google Threat Intelligence |
TL;DR
A critical security flaw in Sogou Input Method enabled attackers to compromise desktop computers through a single link. The exploit chain chained an unvalidated protocol parameter with an outdated browser engine to bypass defenses. Tencent released an automatic software patch after security researchers disclosed the vulnerability.
What Happened During the Intrusions
The attack chain began when a target received a specially crafted web address. When the user clicked the link, Windows dispatched the request to the local protocol handler. This program verified the target executable but failed to sanitize command-line arguments. Consequently, the handler passed untrusted parameters directly to the application.
The injected arguments instructed the application to display a custom skin marketplace page. Unlike standard configuration windows, this specific page initializes an embedded Chromium browser engine. The application loaded an attacker-controlled address without validating the domain or protocol scheme. Furthermore, the embedded browser ran an outdated Chromium version from March 2020.

The software developers had disabled the native browser sandbox completely. In addition, they disabled standard web security controls like the same-origin policy. As Gen Threat Labs noted in their analysis, “The entire chain requires nothing more than a single click on a link.” The external web page delivered an exploit for an older V8 memory bug.
Who is Behind the Campaign
Security researchers attribute this activity to UNC3569 with moderate confidence. Threat intelligence analysts at Google track UNC3569 as a China-nexus espionage group. The group frequently targets education, government, finance, and technology organizations across East and Southeast Asia. Additionally, public research links the group to leaked records from Chinese contractor i-SOON.
During these intrusions, the group deployed the GRAYRABBIT backdoor onto compromised workstations. The exploit shellcode downloaded three core files from a cloud server. These files included a legitimate 7-Zip binary and a malicious dynamic link library. The attackers used binary sideloading to execute their implant without triggering defensive alarms.
The payload loader verified the running environment before decrypting the final implant. Specifically, the loader checked the total process count to detect automated analysis sandboxes. If the system passed this check, the loader decrypted the backdoor into memory. Afterwards, the installer deleted its files from disk using alternate data streams.
Impact and Scale of the Threat
Sogou Input Method maintains hundreds of millions of desktop installations worldwide. Consequently, any unpatched client remained open to complete system takeover. The GRAYRABBIT backdoor grants intruders interactive command shells and remote file management capabilities. Operators can also load modular plugins at runtime to expand their access.
Threat actors focused their intrusions on sensitive organizational targets. However, the underlying flaw exposed all desktop users who encountered the malicious links. Investigators have not confirmed any direct financial ransom demands. Therefore, reported monetary costs remain unverified claims.
How Users and Organizations Stay Protected
Gen Threat Labs reported the vulnerability to Tencent on April 9, 2026. Tencent acted quickly and published an updated release twelve days later. In their official statement, “Tencent characterized the vulnerability’s impact as limited, noting that the exploitation chain is ‘relatively complex’ and that it requires ‘social engineering tactics to induce the user to actively authorize the browser’s pop-up prompt.'”
The software update fixed the parameter handling inside the protocol dispatcher. However, Gen Threat Labs warned that internal risks remain. The researchers stated, “While the update blocks the exploit path we observed, the underlying browser component remains outdated, continues to run without sandboxing, and still has important browser security controls disabled.”
Users should confirm that Sogou Input Method runs version 16.3.0.3498 or later. In addition, network administrators should restrict custom protocol handlers in corporate browser policies. Security teams must monitor endpoints for unexpected process execution from input method directories. Finally, organizations should inspect application directories for unauthorized dynamic link libraries.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!