Sogou Input Method backdoor attack by China-linked attackers
A China-linked hacking group exploited a flaw in Sogou Input Method, a popular Chinese-character typing tool for Windows, to secretly install a backdoor on users' computers. Once installed, the backdoor lets attackers do anything the victim's logged-in account can do.
- Report priority
- Medium
- Targets
- Sogou Input Method
How it works
- The attackers sent victims a fake link that, when clicked, exploited a flaw in Sogou Input Method.
- This flaw let the attackers install a backdoor on the victim's Windows PC.
- The backdoor then gave the attackers full control over the victim's logged-in account, letting them steal files, take screenshots, or run other commands.
What to do
Check your installed version of Sogou Input Method by going to Control Panel > Programs > Uninstall a program and look for Sogou Input Method. If it is installed, uninstall it immediately and scan your computer with a trusted antivirus program.
Uninstall Sogou Input Method from your Windows PC by going to Control Panel > Programs > Uninstall a program. Then, scan your computer with a trusted antivirus program like Windows Defender or Malwarebytes to remove any potential backdoor. Keep your operating system and other software updated to reduce the risk of future attacks.
Technical details
The attackers sent victims a malicious link via email or messaging apps. When clicked, the link triggered the Sogou Input Method flaw, installing the GRAYRABBIT backdoor on the victim's Windows PC without their knowledge.
A China-linked threat actor group, tracked as UNC3569, exploited a remote code execution (RCE) vulnerability in Sogou Input Method, a popular Chinese IME for Windows. The flaw allowed attackers to execute arbitrary commands with the privileges of the logged-in user by tricking victims into opening a specially crafted link. This enabled full system compromise, including installing persistent backdoors like GRAYRABBIT.
The vulnerability was documented under NEWS-a234b5ac9e19ca8fff and was actively weaponized in the wild. No CVE ID or CVSS score was assigned in the source. The affected version was unspecified, but the attack was confirmed against widely deployed Sogou Input Method editions.
No patch or fixed version was disclosed in the provided details.