Sogou CVE-2026-51990: UNC3569 one-click RCE via custom protocol handler and outdated embedded Chromium, GrayRabbit backdoor deployed, patch blocks exploit chain but root Chromium flaw remains      Revolut: passport copies, verification selfies, and full Bitcoin transaction histories handed to an unauthorized party after a fraudulent request from a real government agency email domain      Microsoft: two concurrent abuse campaigns using trusted infrastructure — CEO impersonation ACH fraud and passkey-themed blob URL phishing that leaves no static page to detect      Sogou CVE-2026-51990: UNC3569 one-click RCE via custom protocol handler and outdated embedded Chromium, GrayRabbit backdoor deployed, patch blocks exploit chain but root Chromium flaw remains      Revolut: passport copies, verification selfies, and full Bitcoin transaction histories handed to an unauthorized party after a fraudulent request from a real government agency email domain      Microsoft: two concurrent abuse campaigns using trusted infrastructure — CEO impersonation ACH fraud and passkey-themed blob URL phishing that leaves no static page to detect     
CyberSipTM
Intelligence without the noise
Issue No. 130
September 15, 2026
3 items · past 24h
<5 min read
Today's picture

UNC3569, a China-aligned espionage group, is exploiting CVE-2026-51990, a one-click RCE in Tencent's Sogou Input Method discovered by Gen Digital during a live intrusion, which chains three weaknesses in the application's custom protocol handler and outdated embedded Chromium engine to execute code when a target clicks a crafted link, deploying the GrayRabbit backdoor against government, education, technology, and finance targets across East and Southeast Asia, with the April 2026 patch blocking the specific exploit chain while leaving the underlying Chromium vulnerability in the software. Revolut confirmed it handed KYC records including passport copies, verification selfies, and complete Bitcoin transaction histories to an unauthorized third party after receiving fraudulent information requests sent from a legitimate government agency email domain, no systems breach involved but a full legal-request data package delivered to whoever controls that email account. Microsoft disclosed two simultaneous abuse campaigns: financial fraud actors sending CEO-impersonation emails to trigger ACH transfers and a separate group using passkey-themed phishing with blob URLs that render entirely in the victim's browser and leave no static phishing page for URL filters to detect.

Today's intelligence
3 items
01 HighSogou Input MethodUNC3569 / GrayRabbit
UNC3569 is exploiting a one-click RCE in Tencent's Sogou Input Method to deploy the GrayRabbit backdoor — Gen Digital found it in a live intrusion
CVE-2026-51990 chains three weaknesses in Sogou's custom sgbiz: protocol handler and its outdated, unsandboxed embedded Chromium engine. One crafted link, one click, code execution. The April 2026 patch blocks the specific exploit chain but left the underlying Chromium configuration unchanged. Organizations with Sogou installed — particularly in any environment touching East or Southeast Asian networks — should verify the version and check for GrayRabbit IoCs.
CVECVE-2026-51990
Critical RCE
One-click
ActorUNC3569
China-aligned
hacker-for-hire
PayloadGrayRabbit backdoor
Remote shell
File transfer
Modular plugins
RC4 TCP on 443
TargetsGovt, education
tech, finance
East/SE Asia
Patch statusv16.3.0.3498
blocks exploit chain
Chromium root
cause unchanged
Gen Threat Labs discovered CVE-2026-51990 while investigating a live intrusion by UNC3569, a Chinese hacker-for-hire group Google Threat Intelligence has tracked since 2021. The initial access traced back unexpectedly to Sogou Input Method, one of the most widely used Chinese-language input method editors with hundreds of millions of Windows installations. The vulnerability chains three weaknesses: unvalidated command-line argument injection into the sgbiz: custom protocol handler, unrestricted URL navigation within that handler, and an outdated and unsandboxed Chromium browser engine embedded in the application. When a target clicks a crafted sgbiz: link, Windows launches Sogou's biz_helper.exe protocol handler, which passes the attacker's command-line arguments to the embedded Chromium instance without validation. That Chromium instance, running without a sandbox, executes attacker-controlled code. The exploit drops a malicious 7z.dll loader that decrypts and loads GrayRabbit (core.dll), UNC3569's first-stage backdoor in use since 2021. GrayRabbit provides a remote shell, file transfer in both directions, dynamic plugin loading from the attacker's C2, and communicates via RC4-encrypted TCP on port 443. Gen reported the vulnerability to Tencent on April 9. Tencent patched it in version 16.3.0.3498 via automatic update. The patch added URL validation in the protocol handler but did not update the Chromium configuration. Gen confirmed as of September 10 that the Chromium version and configuration remain unchanged, meaning a different exploitation path through the same underlying component cannot be ruled out. IoCs: SHA-256 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 (loader DLL written as 7z.dll), SHA-256 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e (encrypted payload named p), SHA-256 d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a (GrayRabbit backdoor, internal name core.dll).
The Sogou Input Method attack surface is unusual. This is not an enterprise server or a network device: it is productivity software with hundreds of millions of installations, widely used in corporate environments that serve Chinese-language users or operate in markets with significant Mandarin-speaking workforces. The embedded outdated Chromium is the structural issue the patch did not fully resolve: an unsandboxed browser engine inside a widely installed desktop application is an unusual and persistent attack surface that no update to the protocol handler validation fully eliminates. For threat intelligence teams tracking UNC3569, GrayRabbit is explicitly the group's first-stage implant used as the initial foothold before deploying additional tooling. Detecting GrayRabbit means detecting the earliest stage of a UNC3569 intrusion.
Gen's research notes two gaps in the public record that matter operationally: neither Gen nor Tencent has specified which Sogou versions below 16.3.0.3498 are affected, and neither has documented how to verify which version is installed on a given machine. The loader DLL deletes itself after execution, so the malicious 7z.dll may not be on disk on a compromised machine. Hunting should focus on the three SHA-256 hashes above, anomalous 7-Zip process executions, unexpected files in C:\Users\Public\Documents\, and outbound RC4-encrypted connections to port 443 from processes associated with Sogou.
  • Verify Sogou Input Method is updated to version 16.3.0.3498 or higher on all endpoints where it is installed. The automatic update pushed by Tencent in April 2026 should have reached all users, but verify rather than assume in managed environments where update policies may interfere with automatic delivery.
  • Hunt for GrayRabbit IoCs on any endpoint running Sogou, especially those in environments touching East or Southeast Asian networks or government, education, technology, or finance sectors. Check the three SHA-256 hashes above, unexpected 7-Zip executions, files in C:\Users\Public\Documents\, and outbound connections to port 443 from Sogou-related processes. The loader self-deletes, so absence of the DLL does not confirm the host is clean.
One crafted link. One click. Backdoor installed. Gen found it inside a live UNC3569 intrusion. The patch blocks this specific chain but the embedded Chromium that made it possible is still outdated and unsandboxed. Update Sogou and hunt the IoCs — especially on endpoints where the loader may have self-deleted before detection.
02 HighRevolutFraudulent Legal Request
Revolut handed passport copies, verification selfies, and full Bitcoin transaction histories to a fraudulent government email — no systems were breached, the data was simply given away
This is not a technical breach. An attacker using a compromised or unauthorized account inside a real government agency's email domain sent lawful-intercept-style data requests to Revolut. Revolut's systems authenticated the domain, found the requests to be from a government agency, and complied. The attacker received complete KYC packages. The FBI warned in 2024 that exactly this attack pattern — fraudulent emergency data requests via compromised government email accounts — was being sold as a service.
MethodFraudulent data
requests from
real govt agency
email domain
Data exposedPassport / licence
copies, verification
selfies, DOB,
address, phone
Account statements
IBAN, full Bitcoin
transaction history
Systems breachedNo
ConfirmedSept 12, 2026
Revolut to
TechCrunch
Revolut confirmed on September 12 that it disclosed sensitive customer data to an unauthorized third party after receiving fraudulent information requests sent from an email account operating within a legitimate government agency's domain infrastructure. Revolut describes it as a sophisticated external impersonation scam in which the attacker used a real government agency email address. The requests passed Revolut's standard domain authentication checks because the domain genuinely belonged to a government agency. The data Revolut handed over is precisely what financial institutions collect for Know Your Customer compliance: full name, date of birth, postal address, email address, phone number, copies of passport or driver's license, facial verification selfies taken during onboarding, account statements including the IBAN, account opening date, withdrawal records, and the complete transaction history including Bitcoin wallet reference numbers. Revolut says a limited number of customers are affected, has not named the specific government agency or markets involved, and confirms customer funds and passwords were not compromised. The customer notification was first flagged publicly by crypto investigator ZachXBT on September 12. The FBI published a warning in November 2024 that compromised government email accounts were being purchased and used specifically for fraudulent emergency data requests of this type.
The Revolut incident illustrates a class of attack that does not trigger any technical security control: it exploits the legitimate legal process channel rather than any vulnerability in the target's systems. Regulated financial institutions are legally obligated to respond to government data requests. When the request arrives from a verified government domain, domain-based authentication provides no signal of fraud. The attacker receives a complete, verified identity package that includes the KYC documentation required to impersonate the victim credibly in financial fraud. A passport copy plus a verification selfie plus a complete transaction history including Bitcoin addresses is not a partial data exposure; it is everything needed to impersonate someone's financial identity, open accounts in their name, or conduct targeted spear-phishing using precise financial details.
Whoever holds the data Revolut handed over now has a complete verified identity package for each affected customer. The second-order risk is not the data exposure itself — it is what comes next. Targeted phishing using precise personal and financial details, SIM-swapping attempts, account takeover via identity verification, and credible impersonation of Revolut support to obtain credentials are all enabled by a passport plus a selfie plus a transaction history. Affected Revolut customers receiving the breach notification should treat any inbound communication purporting to be from Revolut, a financial institution, or a government agency as potentially adversarial, regardless of how accurate the personal details it contains appear to be.
  • Financial institutions and regulated fintechs should assess their legal data request handling procedures specifically for the scenario where the requesting email domain is legitimate but the individual account sending the request is unauthorized. Out-of-band verification of high-sensitivity requests through a separate contact channel at the requesting agency, rather than relying solely on domain authentication, is the control this incident demonstrates is necessary.
  • Affected Revolut customers should treat the exposed data as permanently compromised. Any inbound contact claiming to be from Revolut or a regulatory body that references specific personal or financial details from the account should be treated as a likely targeted social engineering attempt. Contact Revolut through official channels — not through any link or number provided in inbound communications — to confirm any claimed action.
Nobody breached Revolut. Somebody asked from a real government email address, and Revolut answered with passports, selfies, and complete Bitcoin transaction histories. The FBI warned this playbook was being sold in 2024. The data package those customers' identities are now in is exactly what you need to impersonate them credibly. The fraud wave comes next.
03 MicrosoftTrusted Infrastructure Abuse
Microsoft disclosed two concurrent campaigns that both defeat standard detection by routing attacks through trusted infrastructure
Two separate campaigns, disclosed together by Microsoft. One: financial fraud actors impersonating CEOs via third-party email delivery services to trigger ACH transfers, sending over a million emails between August 3–5. Two: a group using passkey-themed phishing pages hosted as blob: URLs inside the victim's own browser, which generates no static URL for filtering to detect and renders only in that browser session. Both succeed by routing attacks through infrastructure that security controls are designed to trust.
Campaign 1CEO impersonation
via 3rd-party email
infrastructure
ACH fraud target
1M+ emails Aug 3-5
Campaign 2Passkey phishing
via blob: URLs
Renders in browser
No static URL
Microsoft cloud
account hijack
Detection gapBoth use trusted
infrastructure that
URL/domain filters
are designed
to allow
Microsoft disclosed details of two concurrent abuse campaigns on September 13. The first campaign used third-party bulk email delivery infrastructure: the same services organizations use for legitimate marketing, to send CEO-impersonation emails to accounts payable departments, targeting them for ACH transfer fraud by impersonating the CEO requesting a ServiceNow subscription payment. Routing through legitimate email delivery infrastructure means the sending domain passes SPF, DKIM, and DMARC checks. Microsoft observed over one million such emails sent between August 3 and August 5. The second campaign uses passkey-themed social engineering to hijack Microsoft 365 cloud accounts. The specific technique is blob: URL phishing: the attacker sends a link that generates the phishing page as a blob: URL object rendered entirely in the victim's local browser memory. A blob: URL is a reference to a locally-generated object, not a remote server. It therefore has no static URL a proxy, email filter, or URL reputation service can evaluate; the page does not exist at any network-accessible address. The phishing page presents a passkey authentication prompt, captures the submitted credentials or session token, and hijacks the Microsoft cloud account. Microsoft identified invisible Unicode characters being used in subject lines to bypass phishing keyword filters in the same campaign cluster.
Both campaigns represent the same underlying attacker strategy: route the attack through infrastructure that defenders have configured their tools to trust. Legitimate bulk email delivery platforms pass authentication checks by design. Blob: URLs have no network-accessible address to inspect by design. Invisible Unicode characters pass through keyword filters because they are not the visible characters those filters match. Each of these techniques defeats a specific control that organizations depend on without requiring any vulnerability exploitation; they exploit the gap between what the control was designed to check and what the attacker actually sends.
  • For the ACH fraud campaign: wire transfer and ACH request workflows should require out-of-band confirmation for any payment request above a defined threshold, regardless of whether the requesting email passed authentication. A CEO-impersonation email that passes SPF, DKIM, and DMARC is indistinguishable from a legitimate email by technical controls alone; the control that catches it is a human phone call to the requester through a known-good number.
  • For the passkey phishing campaign: enforce phishing-resistant MFA such as hardware security keys or device-bound passkeys for Microsoft 365 access. Blob: URL phishing that captures a session token can bypass TOTP-based MFA if the attacker uses the token immediately in an adversary-in-the-middle relay. Conditional Access policies that verify device compliance and restrict token reuse reduce the value of a stolen session token even when the phishing page cannot be blocked by URL inspection.
Both campaigns win by routing through infrastructure defenders trust. Legitimate email delivery clears authentication checks. Blob: URLs have no address to filter. The solution to ACH fraud is a phone call. The solution to blob: URL phishing is phishing-resistant MFA that survives token theft.
Cross-source standouts
01
The fraudulent legal request attack: when no system is breached but everything is disclosed
The Revolut incident belongs to a specific and growing attack category that the security industry has not yet named as cleanly as ransomware or phishing: fraudulent legal process abuse. The attacker does not exploit a vulnerability. The attacker does not trick a user into clicking anything. The attacker submits a request through the ordinary legal channel that regulated institutions are required to respond to, from an email address that appears legitimate because the domain genuinely belongs to a government agency. The institution complies because it is legally obligated to comply with government data requests and the request appeared authentic. The FBI's 2024 warning was specific: compromised government email accounts were being sold on criminal forums specifically for use in emergency data request fraud, with financial institutions and technology platforms as the primary targets. The Revolut incident is the pattern playing out as described. The control gap it exposes is not in Revolut's technical systems; it is in the process by which high-sensitivity legal requests are validated. Domain authentication is necessary but not sufficient when the attacker controls a mailbox inside the authentic domain.
02
Sogou and the trusted software attack surface: what outdated embedded components in widely-installed applications mean for endpoint risk
CVE-2026-51990 follows a pattern documented in this brief across Issues 116 (Splunk AI Toolkit pickle deserialization in a trusted AI component), 120 (JFrog Artifactory path traversal as a trusted artifact store), and 123 (Forescout's Claude-assisted PLC exploit porting). In each case the attack surface is not the attacker's tooling but a component inside a trusted, widely-installed piece of software. Sogou's outdated embedded Chromium is particularly concerning because it is a full browser engine, running without a sandbox, inside an application that hundreds of millions of users have installed specifically for productivity. The patch Tencent shipped blocks the specific exploitation chain Gen documented while leaving the Chromium configuration unchanged. That is the same partial-fix dynamic this brief tracked in the Nightmare Eclipse series (ShieldCrash bypassing the ShieldBreak fix) and in PaperCut's two emergency patches with confirmed bypass paths. The residual risk is that a researcher or attacker identifies a second exploitation path through the same unchanged Chromium component that the current patch did not address.
Still watching
Days 3–7+
GitLab CVE-2026-85706 (Issue 129 · max-severity path traversal, exploited day after disclosure, mass exploitation imminent per WatchTowr) — patch immediately. Hunt POST requests to /api/v4/projects/{id}/repository/commits/ containing file.path parameters. Now compounded by CVE-2026-19478 active simultaneously.
Day 3
ShieldCrash (ShieldBreak bypass) (Issue 126 · Nightmare Eclipse, no CVE yet, SYSTEM-level file read on latest patched Windows) — ShieldBreak CVE-2026-69414 patched. ShieldCrash unpatched. Monitor MSRC. Keep behavioral detection for the series active.
Day 7
SAP OVERPASS CVE-2026-44756 (Issue 126 · CVSS 10.0, unauthenticated SAP kernel EPP RCE) — apply patch per SAP Note 3500180. Restrict EPP endpoint to trusted networks. No confirmed exploitation yet; prior CVSS 10.0 SAP flaws moved to exploitation quickly.
Day 7
StyleSmuggler CVE-2026-75650 (Issue 125 · CVSS 10.0, Magento/Adobe Commerce, actively exploited since September 4) — apply composer patch VULN-39341. Rotate encryption key and all derived credentials. Run eComscan for the Linux backdoor on the OS, not only the web root.
Day 7+