Lily
Anne

One Click on Windows Opens the Door to GRAYRABBIT

Lily Anne

Sep 18, 2026

5 min read

One Click on Windows Opens the Door to GRAYRABBIT

TL; DR

CVE-2026-51990 turns Tencent’s Sogou Input Method into a one-click Windows entry point for GRAYRABBIT malware through a crafted link and vulnerable embedded browser components.

  • GRAYRABBIT supports process execution, reverse shells, file transfers, system reconnaissance, and in-memory plugin loading after compromise.
  • Enterprises should locate Sogou installations, verify the fixed version, investigate suspicious execution and DLL activity, and contain confirmed compromises separately from patch remediation.
  • Hexnode UEM can support application inventory and posture checks, while Hexnode XDR provides process-tree investigation and endpoint containment actions.

GRAYRABBIT malware is reaching Windows endpoints through a tool employees use to type Chinese characters. Gen Threat Labs observed UNC3569 exploiting CVE-2026-51990 in Tencent’s Sogou Input Method through a crafted link.

The vulnerability enables one-click remote code execution, turning an everyday desktop utility into an entry point for attackers. Tencent has released a fix, but organizations must identify affected installations and investigate possible compromise.

For IT and security teams, the incident highlights a practical gap: operating-system patching alone cannot address vulnerable components bundled inside third-party applications.

Strengthen Endpoint Security with Hexnode

How the Sogou flaw delivers GRAYRABBIT malware

The attack combines three weaknesses: unsafe argument handling, unrestricted web navigation, and an outdated embedded browser.

When a victim clicks a crafted sgbiz: link, Windows invokes Sogou’s biz_helper.exe protocol handler. The handler checks the requested module but fails to validate the parameter value passed to SGMyInput.exe. Attackers use that gap to inject command-line arguments.

Those arguments open the skincenter component and direct its Chromium Embedded Framework webview to an attacker-controlled page. The embedded Chromium 80 engine runs without a sandbox and disables important web-security protections. The malicious page exploits a known V8 vulnerability to execute code.

The follow-on payload downloads a legitimate 7-Zip executable, a malicious DLL, and an encrypted backdoor payload. The executable sideloads the attacker’s DLL, which loads the final backdoor into memory.

What GRAYRABBIT malware enables after compromise

The backdoor supports process execution, interactive reverse shells, file uploads and downloads, and system and user information collection. It also loads plugins reflectively in memory, allowing attackers to extend its capabilities.

Defenders should monitor biz_helper.exe launching SGMyInput.exe with unusual command-line arguments, particularly those opening skincenter and specifying an unfamiliar URL. Investigate unexpected outbound connections from the process hosting the skincenter webview. Correlate these indicators with suspicious DLL loading and unauthorized file movement to assess the scope of compromise.

cybersecurity-kit

Cybersecurity kit

Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.

Download the Resource Kit

What should enterprise teams do now?

Tencent fixed the reported entry path in Sogou Input Method version 16.3.0.3498. However, researchers warn that the underlying embedded browser remains outdated and unsandboxed. Updating closes the disclosed path; it does not resolve every architectural concern.

Prioritize these actions:

  • Locate installations: Check corporate laptops, regional-office endpoints, and contractor devices within your authorized management scope.
  • Verify remediation: Deploy the fixed release or a later vendor-supported version, then confirm the installed version.
  • Review business need: Remove unnecessary installations through your approved software-management process.
  • Investigate exposure: Review biz_helper.exeSGMyInput.exe execution chains, unusual URL arguments, and unexpected outbound connections associated with the skincenter webview.
  • Contain confirmed compromise: Preserve evidence, isolate affected endpoints, and investigate associated accounts and systems.

Assign an owner and deadline to each affected device. Record update failures and unavailable endpoints as open exceptions. Treat successful patch deployment and completed incident investigation as separate closure requirements.

How Hexnode supports exposure reduction and response

Hexnode UEM and Hexnode XDR support complementary parts of this workflow.

Enterprise priority Hexnode capability Practical application
Locate relevant software Hexnode UEM All Applications report Identify installed applications and open the associated device list to scope follow-up.
Review endpoint posture Hexnode UEM Compliance Policy Evaluate configured criteria, including Windows BitLocker status, to identify baseline gaps.
Investigate execution Hexnode XDR Process Tree Examine parent-child relationships associated with a detected threat, alongside command-line details.
Contain malicious activity Hexnode XDR remediation actions (Kill Process / Kill Process Tree, Isolate Device, Quarantine File) Administrators can isolate endpoints, terminate processes, and quarantine malicious files.

Use these controls to support a defined response process. A compliant device status does not establish that Sogou has the fixed version, and the documented capabilities do not establish campaign-specific detection coverage. Security teams must validate application remediation and assess the evidence before initiating response actions.

FAQs

CVE-2026-51990 allows attackers to abuse Sogou Input Method through a crafted sgbiz: link. The attack manipulates command-line arguments to open an attacker-controlled page inside Sogou’s outdated, unsandboxed embedded Chromium browser, where further exploitation leads to code execution.

Tencent fixed the reported vulnerability path in Sogou Input Method version 16.3.0.3498. Organizations should deploy that release or a later vendor-supported version and verify the installed version on affected endpoints.

No. Updating closes the disclosed exploitation path, but it does not establish that an endpoint was not compromised before remediation. Security teams should separately investigate suspicious Sogou execution chains, DLL activity, network connections and file movement.

Close the third-party application gap

CVE-2026-51990 shows how a routine desktop application can expose an endpoint through components users rarely see. Enterprises should connect application inventory, verified updates, process investigation, and containment within one accountable workflow. That approach helps teams address both the vulnerable installation and any intrusion that occurred before remediation.

Share

Lily Anne

Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.