
highThreat Actors
China-Linked UNC3569 Exploits Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
A China-linked threat actor tracked as UNC3569 has been observed exploiting a vulnerability in Sogou Input Method, a popular Chinese character input tool for Windows, to install the GRAYRABBIT backdoor on victims' systems. The attack chain, detailed by Gen Digital, starts with a malicious link and grants the attacker the same privileges as the logged-in user, potentially leading to data theft and further compromise. Tencent, the owner of Sogou, has not yet issued a public patch or advisory.
The Hacker News2 min read