A Chinese-linked hacking group exploited a vulnerability in Sogou Input Method, a widely used tool for typing Chinese characters on Windows, to install a backdoor on victims' computers, according to security company Gen Digital's research published Thursday This article explores discovered browser safeguards. . Gen uncovered a vulnerability while analyzing a live cyber intrusion by UNC3569, a group linked to China and operating in the country's hacking-for-rent market.
Gen discovered that two of the browser's safeguards have been disabled and incorporated into the code: the sandbox, which typically keeps a compromised web page isolated from the rest of the computer, and the same-origin policy, which prevents a page from accessing data from other sites.
In their response, Tencent described the chain as relatively complex and stated that an attacker would need social engineering to get the user to "actively authorize the browser's pop-up prompt." Browsers based on Chromium display a confirmation prompt before passing a link to an external program, and users can choose to opt out for specific sites. Gen published these indicators: SHA-256 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 malicious DLL loader, written to disk as 7z.dll SHA-256 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e encrypted payload file, named p SHA-256 d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor, internal name core.dll Domain mail.uaiubifas[.
]top backdoor command server, port 443 Domain noht1ng[. ]top hosted the exploit page IP 8.218.50[. ]207 staging server, Alibaba Cloud Hong Kong Path C:\Users\Public\Documents\ where the three files were written












