China-linked threat actor UNC3569 exploited a zero-day vulnerability in Sogou Input Method to deploy the GRAYRABBIT backdoor on Windows systems, according to research from Gen Digital published Thursday.

Sogou Input Method ranks among the most widely installed typing tools for Chinese character input on Windows globally. The vulnerability allowed attackers to execute arbitrary code with the privileges of the logged-in user after victims clicked a malicious link. Once deployed, GRAYRABBIT granted attackers full command execution on compromised machines, enabling them to steal data, install additional malware, or maintain persistent access.

Gen Digital's research identified UNC3569 as a China-based operation conducting the attacks. The group sent crafted links to targets, likely through email or messaging platforms. When clicked, the links triggered the Sogou Input Method flaw, which automatically installed the GRAYRABBIT backdoor without user knowledge or consent. The attack chain bypassed Windows security features by leveraging the input method's elevated privileges.

Sogou Input Method, owned by Chinese internet company Tencent, serves hundreds of millions of users across mainland China, Taiwan, Singapore, and the diaspora. The tool's deep integration into Windows systems and trusted status made it an attractive vector for initial compromise. Security researchers estimate the vulnerability affected all recent versions of the software until patching.

The attack pattern reflects China's persistent interest in targeting diaspora communities and technology sector employees. By compromising input method software, attackers gained access to keystroke data, browsing history, and sensitive documents. The elevated privileges associated with input method services also provided a stable foothold for network reconnaissance.

Gen Digital did not disclose the specific CVE number for the Sogou Input Method flaw at the time of publication, though security teams should treat the vulnerability as critical given its exploitability and the sophistication of UNC3569's deployment infrastructure. The firm notified Tencent before public disclosure.

Organizations with Chinese-speaking employees face elevated risk if those workers use Sogou Input Method on Windows machines connected to corporate networks. System administrators should immediately block or uninstall the software until Tencent releases and validates patches. Endpoint detection systems should monitor for suspicious Sogou Input Method processes spawning command shells or accessing system utilities.

UNC3569's operational security practices suggest a well-resourced group with access to zero-day research. Previous campaigns attributed to the group targeted telecommunications companies, government agencies, and technology firms across Asia-Pacific and North America. The group maintains persistent access for months before exfiltrating data, making early detection and containment essential.

Security teams should apply patches to Sogou Input Method immediately upon release and consider alternative input methods for Windows systems in high-security environments. Endpoint protection solutions must include behavior-based detection for unsigned code execution attempts originating from input method services. Log aggregation tools should flag any Sogou Input Method processes accessing credential stores or file shares.