UNC3569 is a China-nexus threat actor operating primarily from China within the cybercriminal and contractor-for-hire ecosystem. Tracked since at least 2021, it conducts espionage and other intrusion operations against organizations worldwide, with activity concentrated in East and Southeast Asia. Its targets include government, education, technology, finance, media, telecommunications, airlines, heavy industry, energy, and the Chinese gambling industry. Confirmed targeting also includes a U.S. media and entertainment company. The actor commonly obtains initial access by exploiting known vulnerabilities in internet-facing enterprise software, including Microsoft Exchange, IBM Aspera Faspex, Oracle Web Applications Desktop Integrator, VMware products, and Apache software. It also uses trojanized software and supply-chain compromise. Following exploitation, UNC3569 deploys the OXEEYE port-forwarding tool through the SIDESTEP launcher, uses Cobalt Strike BEACON to establish a foothold, and conducts reconnaissance and lateral movement. Its principal backdoors include GRAYRABBIT, DRAFTGRAPH, and CROSSWALK. Other tooling includes SOGU, TROCHILUS, commercial remote-monitoring software, custom loaders, and public exploitation and scanning utilities. Data collection encompasses system information, browser data, messaging-application data, and screenshots. UNC3569 abuses legitimate cloud and developer platforms, including Microsoft OneDrive and GitHub, for command-and-control and payload delivery. Its evasion techniques include DLL sideloading, encrypted payloads, in-memory execution, anti-analysis checks, and loader self-deletion. It also impersonates recognizable technology brands and organizations in its infrastructure and delivery lures. In 2026, UNC3569 exploited CVE-2026-51990 in Sogou Input Method for Windows to deploy GRAYRABBIT. The one-click attack combined insufficient command-line argument validation in a custom protocol handler, unrestricted navigation in an embedded browser, and exploitation of the V8 vulnerability CVE-2021-38003 in an outdated Chromium component. Subsequent stages used a legitimate 7-Zip executable for DLL sideloading. GRAYRABBIT supports process execution, interactive remote shells, system-information collection, bidirectional file transfer, and modular plugin loading.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
33 malware families attributed to this actor across reporting.
28 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor.
In the observed operation, UNC3569 used a known V8 flaw, CVE-2021-38003, to take control of the outdated browser component.
Delivered scripts observed include CVE-2020-16040 exploitation for Chrome, social engineering pop-ups, Electron JS backdoor delivery, and TCP reverse shell establishment.
Download multiple ProxyShell exploit tools for testing: Proxyshell-auto ... Exploit tool based on CVE-2021-34473, CVE-2021-31206, CVE-2021-34523, CVE-2021-31207 ... proxyshell ... based on the Microsoft Exchange CVE-2021-34473, CVE-2021-34523, CVE-2021-31207.
Since 2021, UNC3569 has exploited popular n-day CVEs in widely used software, such as CVE-2021-44228 and CVE‑2022-21587, to gain access to target organizations.
2 more CVEs tied to this actor tracked in Mallory.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a one-click espionage-oriented intrusion campaign against Windows systems running Sogou Input Method, exploiting the application's unsafe custom-protocol handling and unsandboxed Chromium 80 component to deploy the GRAYRABBIT backdoor.
UNC3569 conducted an active intrusion exploiting Sogou Input Method on Windows to deploy the GRAYRABBIT backdoor. The one-click exploit chain enabled code execution with the signed-in user's permissions, followed by payload retrieval and DLL sideloading. GRAYRABBIT provides system reconnaissance, remote command execution, an interactive shell, file transfers, and additional module loading.
A China-linked, potentially i-SOON-associated threat actor that exploits vulnerabilities in popular software to target government, education, technology, and finance organizations globally. In this campaign, it exploited CVE-2026-51990 in Tencent Sogou Input Method using crafted sgbiz links to obtain system-level code execution and deploy GrayRabbit.
UNC3569 is described as a China-based, China-aligned threat actor operating across cybercrime and cyber contractor-for-hire ecosystems. It is exploiting CVE-2026-51990 in Tencent’s Sogou Input Method for Windows to deploy GrayRabbit through a crafted link. The analyzed backdoor supports remote command execution, interactive reverse shells, file transfers, system and user reconnaissance, and in-memory plugin loading.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.