Cyber Threat Intel 7 min read

The Backdoor Came Through Sogou, Which Sees Every Key You Press

A crafted link was enough. An input method editor is downstream of every application on the machine, and this one is installed across the Chinese-speaking world.

Priya Nair
Data, AI Governance & Policy Analyst
Published 12 Sep 2026, 4:51 PM (SGT)
Share:
Hands resting on a backlit keyboard in a dark room, the keys glowing in colour Hands resting on a backlit keyboard in a dark room, the keys glowing in colour Photo by Tima Miroshnichenko on Pexels
Advertisement

12 SEP 2026 — Gen Digital has disclosed that a China-linked group tracked as UNC3569 exploited a flaw in Sogou Input Method to install a backdoor called GRAYRABBIT, starting from a single crafted link. The targets are government, education, technology and finance, mostly in East and Southeast Asia.

The flaw, CVE-2026-51990, was reported to Tencent on 9 April and fixed by 21 April, shipping to users through automatic update in version 16.3.0.3498. This is therefore not a patch-now story. It is a story about which application was chosen, and why that choice was good.

An input method sees everything

An input method editor is the software between a keyboard and every application on the machine. For Chinese, Japanese and Korean text it is not optional — typing 拼音 and selecting characters requires a program that intercepts each keystroke, offers candidates, and passes the chosen text to whatever has focus.

Almost nothing else sits in that position. A browser sees what happens in the browser. An IME sees the password typed into the browser, the message typed into the chat client, the document typed into the word processor, and the search typed into anything. It runs with the user's privileges, at all times, across every application.

Sogou is one of the most widely installed pieces of software in the Chinese-speaking world. An attacker who compromises it does not need to pick a target application, because the IME is downstream of all of them.

1Click, from link to backdoor
12 daysReport to confirmed fix at Tencent
2021Google has tracked the group since
CVE-2026-51990Fixed in 16.3.0.3498, by auto-update

One click, full user privileges

Gen Digital describes the chain as starting with a crafted link and ending with the attacker able to do anything the logged-in user could do. There is no second stage requiring the victim to open a document, enable macros or approve an installer.

The payload is GRAYRABBIT, which Google describes as the group's usual first step onto a machine. It provides a remote command shell, moves files in both directions, and loads further modules from the attacker's server on demand.

The modular loader is the detail that matters for anyone assessing historical exposure. The capability present on a compromised machine at any moment was whatever the operator chose to send, so the question of what the backdoor did has no fixed answer. It did what it was told, and the record of that lives on the attacker's infrastructure.

Hacker-for-hire changes what China-linked means

Google Threat Intelligence places UNC3569 in China's hacker-for-hire scene and has tracked it since 2021. That phrase is doing specific work and is often read too loosely.

A contractor is not a state agency. It takes commissions, and the customer for any given intrusion may be a government, a company, or a private party with a commercial grievance. So attribution to the group says a fair amount about who ran the operation and much less about who commissioned it.

For a defender the practical consequence is that the targeting is less predictable than a state programme's would be. An organisation that would not expect to interest an intelligence service may still interest a private party who can afford to hire that tooling. The sectors named here — government, education, technology, finance — are broad enough to cover most institutions of any size.

Five months between the fix and the telling

Tencent confirmed the fix on 21 April. The campaign was described publicly in September. That is close to five months in which the vulnerability was closed and the intrusion was not discussed.

There is a defensible reason for it. An input method updates silently and gradually, and naming the flaw while a large installed base was still unpatched would have handed a working target to everyone who had not already found it. Waiting for the patch to propagate is the standard, and defensible, argument for such a delay.

The cost is equally real and gets stated less often. For those five months, any organisation that had been compromised through this chain had no reason to look for it. There was no indicator to hunt, no CVE to correlate against, and no sector advisory. A backdoor that loads arbitrary modules on demand does not stop being useful because the way in has been closed, and the patch does nothing for a machine already carrying the payload.

Advertisement

The trade-off is worth understanding on its own terms: delaying disclosure protects one population at the expense of another, and the decision was taken by the party that found the intrusion, with no external process for weighing it.

Why this region, specifically

The concentration in East and Southeast Asia follows directly from the vector.

An exploit in a Chinese-language input method reaches the people who type Chinese. That population is concentrated in exactly the markets Google names, and within our own readership it includes a great many professionals in Singapore, Malaysia and across the region who run a Chinese IME on a machine that also holds work credentials.

The regional focus here is a direct consequence of the attack surface rather than editorial padding. A campaign exploiting a Chinese-language input method will necessarily have a regional footprint.

What to check, given it is patched

Confirm the version rather than assuming the automatic update ran. Sogou's fix reached users through auto-update from late April, which works on machines that were online, allowed to update, and not running a repackaged build from a third-party download site. Managed corporate images and locked-down desktops are the population where that assumption fails.

For the window between April and whenever a given machine updated, treat exposure as a question about links rather than files. The entry point was a crafted link, so the relevant history is browsing and messaging, not downloads.

The practical action is to update the endpoint inventory. Most organisations track browsers and office suites; few track input methods. That omission is how a program with this much reach comes to be unmanaged, and it costs nothing to correct now that there is a reason to.

What to watch

Whether other input methods draw attention. Gen Digital found this one by investigating a live intrusion rather than by auditing the category, and a class of software that turns out to be worth exploiting once is usually worth exploiting again.

And whether any victim is named. Nothing published so far identifies an organisation, and the sector list is the only indication of who was actually reached.

Advertisement
Priya Nair
Data, AI Governance & Policy Analyst

Priya Nair covers AI governance, data protection, privacy, and digital trust topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Priya Nair is a RECATOOLS editorial persona for AI governance, privacy, and digital trust coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement