Discover how the UNC3569 group exploited the Sogou Input Method backdoor using a single malicious link to deploy GRAYRABBIT malware on vulnerable systems.

Discover how the UNC3569 group exploited the Sogou Input Method backdoor using a single malicious link to deploy GRAYRABBIT malware on vulnerable systems.
GitLab CVSS 10 file read, a ScreenConnect worm, JFrog admin tokens, Sogou 1 click GRAYRABBIT, & a KEV pileup. Patch tonight.
Full Inferlume Report: inferlume.com/reports/dail...
#CTI #ThreatIntel #CISAKEV #GitLab #ScreenConnect #JFrog #MikroTik #UNC3569 #GRAYRABBIT #SOC #SupplyChain
Defend against the CVE-2026-51990 Sogou exploit. Discover how hackers use this one-click flaw to drop backdoors and how to secure your systems today.
#CVE202651990 #SogouInputMethod #CyberSecurity #UNC3569 #InfoSec #EndpointSecurity #ThreatIntel
UNC3569 is exploiting a flaw in Tencent Sogou Input Method for Windows via a crafted link to deploy GrayRabbit backdoor. Tencent has patched the one-click RCE issue in version 16.3.0.3498. #UNC3569 #GrayRabbit #Tencent
Sogou Input Method for Windows was used in a real intrusion campaign.
A crafted link could lead to remote control and file transfer.
Tence…
🚨China-linked UNC3569 exploited a Sogou Input Method flaw to deploy GRAYRABBIT. Gen says a crafted link could reach Sogou's outdated Chromium 80 browser, whose sandbox was disabled. Tencent patched the link handler in April 2026. #UNC3569 #GRAYRABBIT #Cybersecurity
UNC3569 abused Sogou flaw & Chromium 80 to drop GRAYRABBIT—patch now in v16.3.0.3498, risks still lurking. #GRAYRABBIT #UNC3569 #Sogou #Cybersecurity #Vulnerability #China https://thedailytechfeed.com/chinese-apt-unc3569-used-sogou-flaw-to-drop-grayrabbit-backdoor/