A serious security vulnerability in Sogou Input Method has allowed attackers to install a backdoor on Windows computers with just a single click on a malicious link.
The flaw, now patched, was reportedly exploited in real-world attacks before security researchers discovered it.
Researchers at Gen Threat Labs, the research team behind Norton and Avast, uncovered the issue while investigating an intrusion linked to a threat group known as UNC3569. What made the discovery particularly concerning was that the attackers were not exploiting a traditional target such as a web browser or email client. Instead, they were using Sogou Input Method, a popular Chinese-language typing application used on Windows.
The researchers found that Sogou Input Method includes an embedded web browser that supports features such as its virtual skin store. That browser component was based on roughly six-year-old technology and had several important security protections disabled.
A separate weakness allowed attackers to reach the embedded browser from outside the application through specially crafted links. By combining the vulnerabilities, attackers could make the vulnerable component load a malicious webpage, execute code and ultimately install malware on the victim’s computer.
The attack required surprisingly little interaction from the victim. Clicking a specially crafted malicious link could be enough to trigger the entire chain, without requiring the user to download a file, manually execute a program or go through multiple security warnings.
The vulnerability has been tracked as CVE-2026-51990.
Researchers also discovered that the flaw was being actively exploited by UNC3569. The group has been linked to attacks targeting organizations in government, education, technology and financial sectors, particularly across East and Southeast Asia.
In the attacks investigated by Gen Threat Labs, the attackers deployed GRAYRABBIT, a lightweight backdoor that provides remote access to compromised computers. The malware can execute commands, open a remote shell, transfer files, collect system and network information, and load additional modules supplied by the attackers.
GRAYRABBIT also uses several techniques to make detection harder. Researchers found that it can check whether it is running in a security research environment, remove its installer after execution and disguise itself using the name of a legitimate application.
Gen Threat Labs reported the vulnerability to Tencent, the owner of Sogou Input Method, in April 2026. Tencent reportedly developed and released a fix within about two weeks, closing the specific attack path used in the campaign.
However, researchers noted that the underlying embedded browser component itself has not been upgraded. The patch primarily prevents attackers from reaching it through the vulnerable link-handling mechanism, meaning keeping the application updated remains important.
Users should make sure Sogou Input Method is running version 16.3.0.3498 or later. The application updates automatically for many users, but checking the installed version manually is still recommended.
The incident also highlights a broader security problem that often goes unnoticed. Software does not need to be a browser, email client or security application to become an attack surface. Everyday utilities can contain outdated web components and other technologies that attackers may eventually find a way to exploit.
For users, the safest approach is to keep applications updated and treat unexpected links with caution, even when they arrive through familiar messaging or communication platforms. In this case, one seemingly harmless click was enough to give attackers a path to a fully compromised computer.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Source: Gen Threat Labs research, “Gray Rabbits and the Tale of a One-Click Backdoor.”



