Summary
A one-click remote code execution vulnerability in Tencent’s Sogou Input Method, tracked as CVE-2026-51990, has been exploited by the China-nexus threat actor UNC3569 to deploy GrayRabbit malware against targeted organizations. Sogou Input Method is one of the most widely installed Chinese-language input applications in the world, with hundreds of millions of installations across Windows, Android, and iOS platforms. Tencent patched CVE-2026-51990 on April 21, 2026; exploitation was confirmed by Mandiant in September 2026 against unpatched installations. The vulnerability requires a single user interaction — opening a malicious document or visiting a crafted page with Sogou active — to trigger arbitrary code execution.
Timeline
| Date | Event |
|---|---|
| April 21, 2026 | Tencent releases patched version of Sogou Input Method addressing CVE-2026-51990 |
| May-August 2026 | UNC3569 begins exploiting CVE-2026-51990 against unpatched targets; GrayRabbit malware deployed |
| Sep 13, 2026 | Mandiant publishes full attribution report confirming UNC3569 exploitation and GrayRabbit malware family |
What Happened
CVE-2026-51990 is a memory corruption vulnerability in Sogou Input Method’s document processing component. An attacker can exploit it by persuading a target to open a malicious file or navigate to a crafted web page while Sogou is running, triggering arbitrary code execution in the context of the logged-in user. No administrator privileges are required; a single user interaction is the only precondition.
UNC3569, a China-nexus espionage group tracked by Mandiant, used the vulnerability to deploy GrayRabbit, a previously undocumented malware family. GrayRabbit establishes persistence through scheduled tasks and registry modifications, beacons to command-and-control infrastructure over encrypted HTTPS channels, and supports modules for credential harvesting, file exfiltration, and lateral movement. Observed targets include organizations in government, defense contracting, and critical infrastructure sectors in Southeast Asia and the United States.
The attack surface is unusually broad. Sogou Input Method’s install base spans corporate, government, and personal devices across multiple operating systems. Organizations that permit or use Chinese-language input software should treat unpatched Sogou installations as an urgent remediation priority and audit affected systems for indicators of GrayRabbit compromise.
Domain Intelligence
tencent.com — 62.41
tencent.com scores in the low-trust range at 62.41. Tencent is the vendor of the affected Sogou Input Method software and the party that issued the patch on April 21, 2026. One threat intelligence source has flagged tencent.com but the observation has not been independently corroborated; per WarmBadge’s methodology, an unconfirmed single-source flag does not reduce the published score on its own.
The Trust Observatory · thetrustobservatory.com · September 13, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026