China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
중국 해킹 그룹이 Sogou 입력기 결함을 이용해 GRAYRABBIT 백도어를 설치했다.
중국 해킹 그룹 UNC3569가 Windows에서 널리 사용되는 Sogou 입력기의 취약점을 악용하여 피해자의 컴퓨터에 GRAYRABBIT 백도어를 설치했습니다. 이 공격은 조작된 링크로 시작되어 사용자가 수행할 수 있는 모든 작업을 공격자가 할 수 있게 되었습니다. Gen Digital에서 발표한 연구 내용을 기반으로 하며 보안 위협과 관련된 사례로 주목받고 있습니다.
A Chinese hacking group exploited a flaw in Sogou Input Method to install the GRAYRABBIT backdoor.
The China-linked hacking group UNC3569 exploited a vulnerability in Sogou Input Method, a widely used tool for typing Chinese characters on Windows, to deploy the GRAYRABBIT backdoor on victims' computers. The attack began with a crafted link, allowing the attacker to perform any action the logged-in user could do. This incident highlights important security threats associated with software vulnerabilities, as noted in a research report by Gen Digital.