← Back to Feed

Gray Rabbits and the Tale of a One-Click Backdoor

September 10, 2026 · Gen Digital · Severity: CRITICAL

This Gen Digital research article details the GRAYRABBIT backdoor vulnerability in Sogou Input Method that allowed a one-click compromise when users clicked a crafted link. The UNC3569 threat group actively exploited the flaw before it was fixed after responsible disclosure to Tencent. Users are advised to update the software to prevent attacks.

Key Takeaways

  • The GRAYRABBIT backdoor was deployed by the UNC3569 threat group through a one-click vulnerability in Sogou Input Method exploited in the wild, as reported by Gen Digital research. The flaw allowed attackers to compromise systems simply by tricking users into clicking a crafted link.
  • This vulnerability was responsibly disclosed to Tencent, the developer of Sogou Input Method, and has since been fixed. The active exploitation by a known threat group underscores the importance of promptly applying security updates for input method editors and similar software.
  • The GRAYRABBIT backdoor gives attackers persistent remote access to victims' systems, enabling data theft, further malware deployment, or lateral movement. Users of Sogou Input Method should ensure they have the latest version installed to mitigate this one-click exploitation risk.
☕ Buy a Coffee