CVE-2026-51990: China-Linked UNC3569 Exploits Sogou One-Click RCE to Plant GRAYRABBIT Backdoor — Is Your Endpoint Exposed?
An input method editor — software installed to type in Chinese — just became a one-click remote code execution weapon in the hands of a China-linked threat group. That is the story of CVE-2026-51990, a critical vulnerability in Tencent’s Sogou Input Method for Windows that UNC3569 weaponised to plant the GRAYRABBIT backdoor inside government, financial, and technology organisations across East and Southeast Asia. Gen Threat Labs published the full technical report this month, CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 11, 2026, and the targeted corridor puts India squarely in the blast radius.
This is not a theoretical concern. UNC3569 was caught mid-intrusion. The attack was already happening when Gen’s researchers traced the initial access back to a process chain that started inside a legitimate, widely installed application. If your organisation has China-desk staff, joint-venture partnerships, translation teams, or contractors who installed Sogou at any point, you need to act today.
- CVE-2026-51990 in Tencent Sogou Input Method for Windows enables one-click remote code execution via a crafted
sgbiz:URI — no privilege required from the attacker. - The exploit chains three independent weaknesses, including a six-year-old unpatched Chromium 80 browser engine embedded inside the application.
- China-linked hacker-for-hire group UNC3569 deployed the GRAYRABBIT backdoor against government, education, technology, and finance targets across East and Southeast Asia.
- CISA added CVE-2026-51990 to its KEV catalog on September 11, 2026 — confirmed active exploitation.
- The patch (version 16.3.0.3498) was released by Tencent on April 21, 2026. Update all endpoints immediately or remove Sogou entirely if there is no business justification.
How CVE-2026-51990 Works: A Three-Step Exploit You Can Trigger With a Link
The elegance of CVE-2026-51990 is that no single piece of it looks extraordinary. The catastrophe emerges from combining three individually mediocre weaknesses into a reliable one-click attack chain.
Step 1 — The sgbiz: URI Handler. When Sogou Input Method installs on Windows, it registers the sgbiz: custom URI scheme and associates it with an internal component called biz_helper.exe. This means any webpage, email, or application on the machine — or in a remote link clicked by a user — can invoke biz_helper.exe directly. The problem: the handler accepts arbitrary command-line arguments without any validation or authentication check. An attacker who crafts a malicious sgbiz: URL can control what arguments biz_helper.exe receives and what it does next.
Step 2 — The Unguarded Webview. biz_helper.exe passes the attacker-supplied URL to an internal Chromium Embedded Framework (CEF) webview. Again, there is no URL restriction or allowlist. The webview will navigate to any resource the attacker specifies — including local files on the victim’s machine. This turns the protocol handler bypass into arbitrary local file access.
Step 3 — A Six-Year-Old Browser. Here is where the attack becomes truly dangerous. The Chromium engine embedded in Sogou Input Method is based on version 80, released in March 2020 — carrying roughly six years of unpatched known vulnerabilities. Tencent has also disabled the sandbox entirely and stripped the same-origin policy. What should be a locked-down, containerised rendering environment is instead an unconstrained code-execution environment running with the privileges of the logged-in user. An attacker navigates the unguarded webview to an attacker-controlled page that exploits the sandboxless Chromium, and arbitrary code runs — silently, instantly, with user-level privileges.
| Layer | Component | Weakness |
|---|---|---|
| 1 | sgbiz: URI → biz_helper.exe |
No input validation; arbitrary argument injection |
| 2 | CEF-based internal webview | No URL restriction; unrestricted local file access |
| 3 | Chromium 80 engine (March 2020) | Sandbox disabled, SOP stripped, 6+ years of unpatched CVEs |
The attack requires nothing more than the target clicking a link. No phishing attachment. No macro. No elevation prompt. A single click on a crafted sgbiz: URL delivers code execution. As Gen Threat Labs noted in their full research report, this is precisely the kind of supply-chain blind spot that organisations with strict perimeter controls still miss — the exploit vector is a trusted, pre-installed application, not an unknown binary.
UNC3569: China’s Hacker-for-Hire Group Is Not Waiting for You to Patch
Google Threat Intelligence tracks UNC3569 as a China-aligned, commercially motivated threat actor — a hacker-for-hire operation that has been active since at least 2021. Unlike purely state-directed APTs that focus narrowly on political intelligence, hacker-for-hire groups sell access and capabilities to multiple clients. This means the targeting set is broader, less predictable, and often more aggressive than traditional espionage actors.
UNC3569 has historically focused on government, education, technology, and finance organisations across East and Southeast Asia. It is not exclusively an East Asian problem: as regional supply chains tighten and India deepens its economic engagement with China-adjacent markets, Indian enterprises with China-desk operations, bilateral trade functions, joint-venture agreements, or Mandarin-language staff are increasingly attractive targets for a group with this profile.
The group discovered and operationalised CVE-2026-51990 before Gen Threat Labs found it during a live intrusion investigation. Gen researchers did not find the vulnerability in a lab — they found it in the middle of a real attack. That fact alone should recalibrate your patching urgency: by the time a CVE is public and in the KEV catalog, it has already been used against real targets.
For context, India has seen a sharp rise in China-linked APT activity targeting government, critical infrastructure, and financial institutions over the past two years. Our earlier analysis of the BlueMoon exploit kit showed how China-aligned groups chain browser and OS vulnerabilities to achieve persistent access — CVE-2026-51990 follows the same playbook: trusted software, browser weaknesses, minimal footprint.
GRAYRABBIT: Small, Quiet, and Already on Your Network
Once CVE-2026-51990 delivers code execution, UNC3569 drops GRAYRABBIT, their first-stage implant. GRAYRABBIT has appeared in UNC3569 intrusions continuously since at least 2021, and its persistence across five years of active campaigns indicates it remains effective against real-world defences.
GRAYRABBIT’s capability set is deliberately lean:
- Reverse shell — outbound connection to attacker C2 for interactive command access
- Process execution — run arbitrary commands or binaries on the infected host
- File transfer — upload files to the C2 server (data exfiltration) or download further tooling
- Plugin loader — fetch and execute additional modules at runtime
- System reconnaissance — collect hardware, OS, network, and user information
- Self-termination — clean exit on command, reducing forensic traces
Simplicity is a defence-evasion strategy. Less code equals fewer signatures, fewer anomalous API calls, and a smaller forensic footprint. GRAYRABBIT establishes a beachhead; the group then decides whether the target justifies heavier follow-on tooling. In the intrusions studied by Gen, GRAYRABBIT persisted undetected for extended periods in environments where Sogou was treated as a background process with no alerting. This is exactly the gap that a mature SOC threat-hunting function must close.
What IT Leaders and Security Teams Should Do Right Now
The patch exists. The question is whether it reached every endpoint in your estate.
- Inventory first. Search every managed endpoint for
sogouinput.exe,biz_helper.exe, and the Sogou Input Method registry key (HKCR\sgbiz). This is your scope. Do not assume auto-updates ran — many enterprise configurations block them. - Update or remove. Upgrade to version 16.3.0.3498 or later if there is a documented business need for Sogou. If there is no such need, remove it entirely and add it to your software blocklist.
- Block the sgbiz: handler. Whether or not you can update immediately, you can delete or restrict the
HKCR\sgbizregistry key to prevent the URI scheme from launchingbiz_helper.exe. This kills the exploit path without removing the application. - Hunt for GRAYRABBIT now. Load the IOCs from Gen Digital’s report into your SIEM and EDR. Look for anomalous outbound connections originating from Sogou processes, unexpected child processes (cmd.exe, powershell.exe) spawned by
biz_helper.exeorsogouinput.exe, and DNS queries to recently registered or uncategorised domains from those processes. - Enforce application allowlisting. A zero-trust endpoint posture means only approved software runs. If Sogou is not on your allowlist, it should not be running. This is foundational — not optional — in any environment that handles sensitive data.
- Segment your network. GRAYRABBIT establishes a foothold, but it needs lateral movement to cause broad damage. Network micro-segmentation — particularly isolating user workstations from domain controllers, financial systems, and development infrastructure — dramatically limits the blast radius of a successful initial compromise.
For additional technical guidance, BleepingComputer’s coverage and The Hacker News analysis provide additional context alongside Gen Digital’s primary research. Microsoft’s MSRC and the CISA KEV catalog are the authoritative sources for patch urgency.
Frequently Asked Questions
Does CVE-2026-51990 only affect Sogou Pinyin, or other Sogou products too?
CVE-2026-51990 is specific to Sogou Input Method for Windows — all editions that include the vulnerable biz_helper.exe component and ship versions prior to 16.3.0.3498. Sogou Browser and other Tencent applications are separately scoped; they may carry their own Chromium-based risks but are not part of this CVE. Verify each product independently.
Tencent pushed an auto-update in April 2026 — doesn’t that mean most users are already patched?
Only if the auto-update actually ran. In enterprise environments, endpoint policies frequently block auto-updates, machines may have been offline at update time, or the update was silently skipped due to a network proxy or disk-space issue. Never assume a patch deployed — verify the version on every endpoint. Check for sogouinput.exe and confirm the file version is 16.3.0.3498 or higher.
My organisation doesn’t actively use Sogou — should I still be concerned?
Yes. Contractor laptops, personal devices brought into the office, machines set up by temporary staff, or inherited endpoints from acquisitions can all carry Sogou without IT knowing. A single unmanaged installation is all UNC3569 needs for initial access. Shadow IT is a zero-trust failure waiting to be exploited.
What does a GRAYRABBIT infection look like in a SIEM or EDR?
Watch for: outbound connections to unknown IPs or recently registered domains originating from biz_helper.exe or sogouinput.exe; unexpected cmd.exe or powershell.exe process trees spawned by these Sogou processes; and unusually large data-upload events from endpoints where Sogou is installed. Gen Digital’s full indicator list is available in their published research report and should be ingested into your detection stack immediately.
One-click attacks via trusted software are not going away — they are getting more sophisticated. UNC3569’s exploitation of CVE-2026-51990 is a textbook example of why endpoint inventory, application control, and zero-trust segmentation are not optional for organisations operating in or alongside East and Southeast Asian markets. India is in UNC3569’s operational geography whether your leadership acknowledges it or not.
If you want an honest assessment of your organisation’s endpoint exposure, application control posture, and SOC readiness to detect threats like GRAYRABBIT, reach out to Sanjay Seth and the P J Networks team for a security assessment →