
UNC3569 Chain Abused Sogou sgbiz: Handler and Unsandboxed Chromium 80 for GRAYRABBIT
UNC3569 leveraged a six-year-old input method component with no input validation or sandboxing to install its initial backdoor across a 455-million-user base. The April 2026 Tencent patch addressed only the link handler while leaving the obsolete browser engine untouched, preserving the same attack surface. This pattern matches prior supply-chain compromises of widely distributed East Asian utilities that prioritize compatibility over isolation.
The attack chain began with an sgbiz: URI that passed unchecked parameters to biz_helper.exe, directing SGMyInput.exe to load its skin store browser at an arbitrary URL. Sogou's bundled Chromium 80 ran with both the sandbox and same-origin policy disabled in compiled code, turning any renderer exploit into immediate user-privilege code execution. Gen Digital observed the full sequence during live response against UNC3569 infrastructure already known for GRAYRABBIT staging.
Gen Digital: Two additional East Asian input-method packages will show equivalent handler-to-browser bypasses by Q3 2027.
Sources (3)
- [1]Gen Digital UNC3569 Sogou Analysis(https://gendigital.com/research/unc3569-sogou-grayrabbit)
- [2]Citizen Lab Sogou Encryption and Reach Report(https://citizenlab.ca/2023/sogou)
- [3]Google Threat Intelligence UNC3569 Profile(https://blog.google/threat-analysis-group/unc3569-2024)