Start your day with intelligence. Get The OODA Daily Pulse.

Home > Briefs > Cyber > Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Sogou input method flaw enables Chinese actor’s backdoor deployment.

A critical vulnerability in Sogou Input Method allowed attackers to trigger system‑level code execution through a crafted sgbiz link that abused unvalidated parameters and an outdated, unsandboxed Chromium engine. Gen Threat Labs said the China‑linked group UNC3569 used the chain to deliver its GrayRabbit backdoor, which provides remote shell access, plugin loading and file exfiltration. Tencent patched the protocol handler in April, but the underlying browser configuration remains outdated and still lacks key security protections. Organizations using the Windows IME were urged to update to version 16.3.0.3498, which was pushed through automatic updates.

Read more:

https://www.securityweek.com/chinese-hackers-exploit-critical-tencent-software-flaw-for-one-click-code-execution/