BlackTree Security · Infrastructure · Automation · AI

One Click in Sogou’s Keyboard Opened a Six-Year-Old Browser to a Spy Group

The first suspicious process in a China-linked intrusion was not a browser or a document reader. It was Sogou Input Method, the everyday Windows tool millions use to type Chinese characters. Gen Threat Labs traced the attack to a crafted link that made the keyboard software open an attacker-controlled page inside its own ageing browser, then install the GRAYRABBIT backdoor.

The entry point has been patched. The research matters because it exposes a less obvious trust boundary: a desktop utility’s custom link handler can turn a click in a web page or message into code running in a privileged, poorly protected embedded browser. The user’s main browser can be fully updated while another browser engine lives inside an unrelated application.

How one link reached an embedded browser

Sogou registers its own sgbiz: protocol on Windows. A link using that scheme is handed to its biz_helper.exe component. Gen found that the handler checked the name of the Sogou executable it would launch but did not validate the arguments supplied to that executable. An attacker could point the legitimate configuration application at the skin marketplace page and supply an arbitrary URL for its embedded Chromium-based webview.

In the observed intrusion, that destination hosted a JavaScript exploit for a V8 flaw disclosed in 2021. It still worked because Sogou bundled Chromium 80, a browser engine dating to 2020. Gen also found the embedded browser’s sandbox disabled and same-origin policy turned off. A successful renderer exploit therefore gained the privileges of the signed-in Windows user rather than being contained by a browser sandbox.

This was a one-click chain, not a zero-click compromise. The victim had to follow the crafted link, and Tencent said some delivery paths required the user to approve a browser prompt. The distinction matters for training and exposure assessment, but it does not turn the application-level failure into a harmless phishing example. The software itself supplied the outdated engine and missing boundary.

What the attackers did after code execution

Gen identified the operator as UNC3569, a China-linked group described by Google Threat Intelligence. The exploit downloaded a legitimate 7-Zip executable, a malicious DLL and an encrypted payload. The DLL was placed beside the legitimate program so that launching it loaded the attacker-controlled code. The final payload was GRAYRABBIT, a backdoor capable of receiving commands, transferring files and loading additional modules.

That is confirmed exploitation in at least the intrusion Gen investigated. The public report does not establish how many people were compromised through this particular route. It would be wrong to turn Sogou’s broad install base into a victim count, or to claim the same attack reached every machine running the keyboard.

The patch closed the link path, not every risky setting

Gen reported the issue to Tencent on 9 April 2026. Tencent said it had completed the fix and deployed version 16.3.0.3498 through automatic update by 21 April. The corrected handler validates URL-bearing switches, requires HTTPS and restricts destinations to an allowlist of Sogou and Tencent domains. Users and organisations should verify that their installed Windows version is at least that build and preferably the latest supported release.

Gen says the patched version still bundles the old Chromium engine with its sandbox disabled and other web security controls weakened. That does not mean the same crafted link remains exploitable after the handler fix. It means the browser component remains a consequential risk if a different route ever makes it load untrusted content. Defenders should inventory desktop applications that ship private browser engines and treat their update status as part of browser security, not as a separate, low-priority application chore.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *