SICHERHEIT & DATENSCHUTZ

China-Linked UNC3569 Exploits Sogou Input Method Vulnerability

China-Linked UNC3569 Exploits Sogou Input Method Vulnerability

A Chinese hacker group has exploited a vulnerability in the Sogou Input Method to install a backdoor.

A new security warning has drawn attention to a Chinese hacker group named UNC3569, which exploited a vulnerability in the Sogou Input Method, a widely used tool for entering Chinese characters on Windows. According to a report from the security company Gen Digital, published on Thursday, the attack began with a specially crafted link that allowed the attackers to install a backdoor on the victims' computers.

The Sogou Input Method is one of the most commonly used input methods in China and is utilized by millions of users. The vulnerability exploited by UNC3569 allowed the attackers to take control of the victims' systems as if they were logged in themselves. This means that the attackers were able to perform any actions that the legitimate user could have performed.

Details of the Attack

The attack began with a link sent to the victims. When users clicked on this link, they were directed to a crafted webpage that exploited the vulnerability in the Sogou Input Method. Gen Digital reported that the attackers were able to install the GRAYRABBIT backdoor through this method, granting them extensive access to the affected systems.

The GRAYRABBIT backdoor allows the attackers to steal data, install malware, and carry out further malicious activities. The security researchers at Gen Digital have noted that the attackers specifically targeted certain organizations and individuals, indicating that this was a well-planned and coordinated attack.

Tencent, the company that owns the Sogou Input Method, has been informed of the vulnerability and is working to close the security gap. However, security researchers have emphasized that the attackers may have already gained access to many systems before the vulnerability was patched. This could pose a significant risk to the affected users.

Reactions and Measures

The discovery of this vulnerability has raised concerns in the cybersecurity community. Experts are warning users to be cautious and not to open suspicious links, especially if they come from unknown senders. The security firm Gen Digital has recommended updating the Sogou Input Method to the latest version to ensure that the security gap is closed.

The Chinese government has not yet commented on the allegations that one of its hacker groups is involved in this attack. The international community is closely monitoring the developments, as such attacks on critical infrastructure and personal data can have significant implications for cybersecurity worldwide.

The security situation regarding software that is widely used in China remains tense. The discovery of this vulnerability in the Sogou Input Method may only be the tip of the iceberg, as many other software products may have similar security vulnerabilities. Users are urged to remain vigilant and regularly check their systems for security updates.

comment Kommentare (0)

Noch keine Kommentare. Schreiben Sie den ersten!

Kommentar hinterlassen