Gen Digital found UNC3569 exploiting a flaw in Sogou Input Method during a live intrusion, and Tencent shipped a fix in version 16.3.0.3498. The attack used a crafted sgbiz: link to reach GRAYRABBIT, the backdoor the group deployed after the click. The flaw is tracked as CVE-2026-51990.
The Windows app registers a custom link handler, and the component that opens the link checks which Sogou module to start but not the arguments passed along with it. That lets attacker-controlled input ride the normal launch path and hand the attacker the same power as the logged-in user, including remote commands and file movement.
For Windows fleets that rely on Sogou Input Method, the exposure is not limited to the app itself. If a host opened one of these crafted links, the patch closes the entry point but does not undo whatever follow-on access GRAYRABBIT already created under that user account.