China-linked hackers slipped a backdoor onto PCs through Sogou, a popular Chinese typing tool
Researchers tracking the cluster as UNC3569 say a single crafted link was enough to hand attackers full control of a victim's Windows machine.

Key points
- Gen Digital researchers published findings on Thursday tying the intrusion set to a China-nexus group tracked as UNC3569.
- The attackers abused a flaw in Sogou Input Method, a tool used by hundreds of millions of people to type Chinese characters on Windows.
- Victims only had to click a crafted link for a backdoor, dubbed GRAYRABBIT, to be installed.
- Once inside, the malware could do anything the logged-in user could do, from reading files to running commands.
- Sogou is owned by Tencent, one of China's largest technology companies.
A China-linked hacking crew used a weakness in one of the most common Chinese typing tools on Windows to plant a backdoor on victims' computers, according to research published Thursday by security firm Gen Digital.
The tool is Sogou Input Method. Think of it as the software that turns keystrokes into Chinese characters on screen. It is installed on a huge share of Windows PCs across mainland China and the diaspora.
Gen Digital, first reported alongside coverage by The Hacker News, attributes the activity with medium confidence to a cluster it labels UNC3569. Other vendors have not yet published overlapping names, so treat the attribution as single-source for now.
How did the attack work?
It started with a link. A victim clicked what looked like an ordinary URL, and the vulnerability in Sogou did the rest, quietly dropping a backdoor the researchers call GRAYRABBIT onto the machine.
A backdoor is a hidden way in. Once GRAYRABBIT is running, the attacker can do whatever the person at the keyboard could do: open documents, copy files, install more tools, or pivot deeper into a company network.
The researchers describe the chain as clean and quiet. No noisy attachment. No obvious warning. Just a poisoned link and a trusted piece of software doing the heavy lifting.
Who is UNC3569?
UNC3569 is a tracking label, not a household name. The "UNC" prefix, borrowed from Mandiant's naming convention, means "uncategorised": a set of activity that looks coherent but has not yet been merged into a named group like Mustang Panda or APT41.
Gen Digital places the cluster in the China-nexus space based on victimology and tooling. That is a statement about capability and likely sponsorship, not a courtroom-grade identification. Overlaps with better-known Chinese espionage crews may emerge as more telemetry comes in.
Should ordinary users be worried?
If you do not use Sogou Input Method, this campaign is not aimed at you. If you do, update the software as soon as Tencent, which owns Sogou, pushes a fix, and be wary of unexpected links, even from contacts you know.
Espionage operators like UNC3569 tend to hunt specific people: journalists, dissidents, officials, executives at firms of interest to Beijing. Mass consumer harm is unlikely. Targeted harm to the right individual can be severe.
What we still do not know
Gen Digital has not published the exact CVE identifier for the Sogou flaw in the material summarised so far, and Tencent has not issued a public advisory at the time of writing. The victim count is also unclear.
A few facts worth pinning down as more reporting lands:
| Detail | What we know |
|---|---|
| Group | Tracked as UNC3569 (Gen Digital) |
| Malware | GRAYRABBIT backdoor |
| Vector | Crafted link abusing Sogou Input Method |
| Disclosure | Gen Digital research, Thursday |
| Attribution confidence | Medium, single vendor |
Expect other threat intelligence teams to weigh in over the coming days. Until then, the sensible read is: capable actor, narrow tooling, targeted intent.



