Trusted Design

Gray Rabbits and the Tale of a One-Click Backdoor

概要

Gen Threat Labs identified CVE-2026-51990, a critical remote code execution vulnerability in Sogou Input Method, a widely-used Chinese-language input editor with hundreds of millions of installations. The exploit chains three weaknesses: unvalidated command-line argument injection in the sgbiz: custom protocol handler, unrestricted URL navigation in a CEF-based webview, and a severely outdated unsandboxed Chromium browser engine from 2020. UNC3569 actively exploited this vulnerability in the wild, using a crafted link to deploy the GRAYRABBIT backdoor. The attack required only a single click, with the exploit leveraging CVE-2021-38003 to achieve code execution. The backdoor included anti-sandbox techniques, self-deletion capabilities, and command-and-control functionality. Tencent patched the vulnerability within twelve days of disclosure, though underlying browser components remain outdated and unsandboxed.

Created: 2026-09-11

Indicators

Indicatorsは見つかっていない。

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

事実ベースの脅威アクターは見つかりませんでした。

このPulseに関連する脅威アクター (推論ベース)

推論ベースの脅威アクターは見つかりませんでした。

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る