{"id":1781,"date":"2026-09-18T14:22:34","date_gmt":"2026-09-18T08:52:34","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1781"},"modified":"2026-09-21T14:29:17","modified_gmt":"2026-09-21T08:59:17","slug":"one-click-on-windows-opens-the-door-to-grayrabbit","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/","title":{"rendered":"One Click on Windows Opens the Door to GRAYRABBIT"},"content":{"rendered":"<p>GRAYRABBIT malware is reaching Windows endpoints through a tool employees use to type Chinese characters. Gen Threat Labs observed UNC3569 exploiting <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-51990?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=grayrabbit_malware\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-51990<\/a> in Tencent\u2019s Sogou Input Method through a crafted link.<\/p>\n<p>The vulnerability enables one-click remote code execution, turning an everyday desktop utility into an entry point for attackers. Tencent has released a fix, but organizations must identify affected installations and investigate possible compromise.<\/p>\n<p>For IT and security teams, the incident highlights a practical gap: operating-system patching alone cannot address vulnerable components bundled inside third-party applications.<\/p>\n<p><center>    \t\t<!-- button style scb6aaa006dc095ba618bc1777be3a12f2a -->\r\n    \t\t<style>\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a, a.scb6aaa006dc095ba618bc1777be3a12f2a{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: ;\r\n    \t\t\t}\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a:hover, a.scb6aaa006dc095ba618bc1777be3a12f2a:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #323232;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/xdr\/\" class=\"ht-shortcodes-button scb6aaa006dc095ba618bc1777be3a12f2a  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tStrengthen Endpoint Security with Hexnode<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How the Sogou flaw delivers GRAYRABBIT malware<\/h2>\n<p>The attack combines three weaknesses: unsafe argument handling, unrestricted web navigation, and an outdated embedded browser.<\/p>\n<p>When a victim clicks a crafted sgbiz: link, Windows invokes Sogou\u2019s biz_helper.exe protocol handler. The handler checks the requested module but fails to validate the parameter value passed to SGMyInput.exe. Attackers use that gap to inject command-line arguments.<\/p>\n<p>Those arguments open the skincenter component and direct its Chromium Embedded Framework webview to an attacker-controlled page. The embedded Chromium 80 engine runs without a sandbox and disables important web-security protections. The malicious page exploits a known V8 vulnerability to execute code.<\/p>\n<p>The follow-on payload downloads a legitimate 7-Zip executable, a malicious DLL, and an encrypted backdoor payload. The executable sideloads the attacker\u2019s DLL, which loads the final backdoor into memory.<\/p>\n<h3>What GRAYRABBIT malware enables after compromise<\/h3>\n<p>The backdoor supports process execution, interactive reverse shells, file uploads and downloads, and system and user information collection. It also loads plugins reflectively in memory, allowing attackers to extend its capabilities.<\/p>\n<p>Defenders should monitor <code>biz_helper.exe<\/code> launching <code>SGMyInput.exe<\/code> with unusual command-line arguments, particularly those opening <code>skincenter<\/code> and specifying an unfamiliar URL. Investigate unexpected outbound connections from the process hosting the <code>skincenter<\/code> webview. Correlate these indicators with suspicious DLL loading and unauthorized file movement to assess the scope of compromise.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-2.webp?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity-kit\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-2.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-2-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-2-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-2-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity-kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            Download the Resource Kit\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>What should enterprise teams do now?<\/h2>\n<p>Tencent fixed the reported entry path in Sogou Input Method version 16.3.0.3498. However, researchers warn that the underlying embedded browser remains outdated and unsandboxed. Updating closes the disclosed path; it does not resolve every architectural concern.<\/p>\n<p>Prioritize these actions:<\/p>\n<ul>\n<li><strong>Locate installations:<\/strong> Check corporate laptops, regional-office endpoints, and contractor devices within your authorized management scope.<\/li>\n<li><strong>Verify remediation<\/strong>: Deploy the fixed release or a later vendor-supported version, then confirm the installed version.<\/li>\n<li><strong>Review business need:<\/strong> Remove unnecessary installations through your approved software-management process.<\/li>\n<li><strong>Investigate exposure:<\/strong> Review <code>biz_helper.exe<\/code> \u2192 <code>SGMyInput.exe<\/code> execution chains, unusual URL arguments, and unexpected outbound connections associated with the <code>skincenter<\/code> webview.<\/li>\n<li><strong>Contain confirmed compromise:<\/strong> Preserve evidence, isolate affected endpoints, and investigate associated accounts and systems.<\/li>\n<\/ul>\n<p>Assign an owner and deadline to each affected device. Record update failures and unavailable endpoints as open exceptions. Treat successful patch deployment and completed incident investigation as separate closure requirements.<\/p>\n<h2>How Hexnode supports exposure reduction and response<\/h2>\n<p>Hexnode UEM and Hexnode XDR support complementary parts of this workflow.<\/p>\n<table style=\"width: 100%; height: 216px;\">\n<thead>\n<tr style=\"height: 24px;\">\n<th style=\"height: 24px;\">Enterprise priority<\/th>\n<th style=\"height: 24px;\">Hexnode capability<\/th>\n<th style=\"height: 24px;\">Practical application<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"height: 48px;\">\n<td style=\"height: 48px;\">Locate relevant software<\/td>\n<td style=\"height: 48px;\"><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> All Applications report<\/td>\n<td style=\"height: 48px;\">Identify installed applications and open the associated device list to scope follow-up.<\/td>\n<\/tr>\n<tr style=\"height: 48px;\">\n<td style=\"height: 48px;\">Review endpoint posture<\/td>\n<td style=\"height: 48px;\">Hexnode UEM Compliance Policy<\/td>\n<td style=\"height: 48px;\">Evaluate configured criteria, including <a href=\"https:\/\/www.hexnode.com\/blogs\/how-to-manage-bitlocker-and-why-should-you-use-it\/\">Windows BitLocker<\/a> status, to identify baseline gaps.<\/td>\n<\/tr>\n<tr style=\"height: 48px;\">\n<td style=\"height: 48px;\">Investigate execution<\/td>\n<td style=\"height: 48px;\">Hexnode XDR Process Tree<\/td>\n<td style=\"height: 48px;\">Examine parent-child relationships associated with a detected threat, alongside command-line details.<\/td>\n<\/tr>\n<tr style=\"height: 48px;\">\n<td style=\"height: 48px;\">Contain malicious activity<\/td>\n<td style=\"height: 48px;\">Hexnode XDR remediation actions (Kill Process \/ Kill Process Tree, Isolate Device, Quarantine File)<\/td>\n<td style=\"height: 48px;\">Administrators can isolate endpoints, terminate processes, and quarantine malicious files.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Use these controls to support a defined response process. A compliant device status does not establish that Sogou has the fixed version, and the documented capabilities do not establish campaign-specific detection coverage. Security teams must validate application remediation and assess the evidence before initiating response actions.<\/p>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How does CVE-2026-51990 deliver GRAYRABBIT malware?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>CVE-2026-51990 allows attackers to abuse Sogou Input Method through a crafted sgbiz: link. The attack manipulates command-line arguments to open an attacker-controlled page inside Sogou\u2019s outdated, unsandboxed embedded Chromium browser, where further exploitation leads to code execution.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Which Sogou Input Method version fixes CVE-2026-51990?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Tencent fixed the reported vulnerability path in Sogou Input Method version 16.3.0.3498. Organizations should deploy that release or a later vendor-supported version and verify the installed version on affected endpoints.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Is updating Sogou Input Method enough after possible GRAYRABBIT exposure?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. Updating closes the disclosed exploitation path, but it does not establish that an endpoint was not compromised before remediation. Security teams should separately investigate suspicious Sogou execution chains, DLL activity, network connections and file movement.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Close the third-party application gap<\/h3>\n<p>CVE-2026-51990 shows how a routine desktop application can expose an endpoint through components users rarely see. Enterprises should connect application inventory, verified updates, process investigation, and containment within one accountable workflow. That approach helps teams address both the vulnerable installation and any intrusion that occurred before remediation.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen Windows Malware Defense<\/h5><p>Secure Windows endpoints, restrict risky apps, and strengthen malware response with Hexnode.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>GRAYRABBIT malware is reaching Windows endpoints through a tool employees use to type Chinese characters&#8230;.<\/p>\n","protected":false},"author":6,"featured_media":1790,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,16],"class_list":["post-1781","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-windows","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>GRAYRABBIT Malware Exploits Sogou Input Method Flaw<\/title>\n<meta name=\"description\" content=\"GRAYRABBIT malware exploits a Sogou Input Method flaw. Learn how the attack works and how to reduce Windows endpoint exposure.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GRAYRABBIT Malware Exploits Sogou Input Method Flaw\" \/>\n<meta property=\"og:description\" content=\"GRAYRABBIT malware exploits a Sogou Input Method flaw. Learn how the attack works and how to reduce Windows endpoint exposure.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-18T08:52:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-21T08:59:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/One-Click-on-Windows-Opens-the-Door-to-GRAYRABBIT.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/one-click-on-windows-opens-the-door-to-grayrabbit\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/one-click-on-windows-opens-the-door-to-grayrabbit\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"One Click on Windows Opens the Door to GRAYRABBIT\",\"datePublished\":\"2026-09-18T08:52:34+00:00\",\"dateModified\":\"2026-09-21T08:59:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/one-click-on-windows-opens-the-door-to-grayrabbit\\\/\"},\"wordCount\":862,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/one-click-on-windows-opens-the-door-to-grayrabbit\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/One-Click-on-Windows-Opens-the-Door-to-GRAYRABBIT.png?format=webp\",\"articleSection\":[\"Malware\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/one-click-on-windows-opens-the-door-to-grayrabbit\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/one-click-on-windows-opens-the-door-to-grayrabbit\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/one-click-on-windows-opens-the-door-to-grayrabbit\\\/\",\"name\":\"GRAYRABBIT Malware Exploits Sogou Input Method Flaw\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/one-click-on-windows-opens-the-door-to-grayrabbit\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/one-click-on-windows-opens-the-door-to-grayrabbit\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/One-Click-on-Windows-Opens-the-Door-to-GRAYRABBIT.png?format=webp\",\"datePublished\":\"2026-09-18T08:52:34+00:00\",\"dateModified\":\"2026-09-21T08:59:17+00:00\",\"description\":\"GRAYRABBIT malware exploits a Sogou Input Method flaw. Learn how the attack works and how to reduce Windows endpoint exposure.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/one-click-on-windows-opens-the-door-to-grayrabbit\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/one-click-on-windows-opens-the-door-to-grayrabbit\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/one-click-on-windows-opens-the-door-to-grayrabbit\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/One-Click-on-Windows-Opens-the-Door-to-GRAYRABBIT.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/One-Click-on-Windows-Opens-the-Door-to-GRAYRABBIT.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"One Click on Windows Opens the Door to GRAYRABBIT\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/one-click-on-windows-opens-the-door-to-grayrabbit\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"One Click on Windows Opens the Door to GRAYRABBIT\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"description\":\"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"GRAYRABBIT Malware Exploits Sogou Input Method Flaw","description":"GRAYRABBIT malware exploits a Sogou Input Method flaw. Learn how the attack works and how to reduce Windows endpoint exposure.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/","og_locale":"en_US","og_type":"article","og_title":"GRAYRABBIT Malware Exploits Sogou Input Method Flaw","og_description":"GRAYRABBIT malware exploits a Sogou Input Method flaw. Learn how the attack works and how to reduce Windows endpoint exposure.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-18T08:52:34+00:00","article_modified_time":"2026-09-21T08:59:17+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/One-Click-on-Windows-Opens-the-Door-to-GRAYRABBIT.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"One Click on Windows Opens the Door to GRAYRABBIT","datePublished":"2026-09-18T08:52:34+00:00","dateModified":"2026-09-21T08:59:17+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/"},"wordCount":862,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/One-Click-on-Windows-Opens-the-Door-to-GRAYRABBIT.png?format=webp","articleSection":["Malware","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/","url":"https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/","name":"GRAYRABBIT Malware Exploits Sogou Input Method Flaw","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/One-Click-on-Windows-Opens-the-Door-to-GRAYRABBIT.png?format=webp","datePublished":"2026-09-18T08:52:34+00:00","dateModified":"2026-09-21T08:59:17+00:00","description":"GRAYRABBIT malware exploits a Sogou Input Method flaw. Learn how the attack works and how to reduce Windows endpoint exposure.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/One-Click-on-Windows-Opens-the-Door-to-GRAYRABBIT.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/One-Click-on-Windows-Opens-the-Door-to-GRAYRABBIT.png?format=webp","width":1340,"height":700,"caption":"One Click on Windows Opens the Door to GRAYRABBIT"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/one-click-on-windows-opens-the-door-to-grayrabbit\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"One Click on Windows Opens the Door to GRAYRABBIT"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"description":"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1781","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1781"}],"version-history":[{"count":4,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1781\/revisions"}],"predecessor-version":[{"id":1820,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1781\/revisions\/1820"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1790"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1781"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1781"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}