GRAYRABBIT is a lightweight, modular Windows backdoor written in C++ and used by UNC3569, a China-linked threat actor operating within the cybercriminal and contractor-for-hire ecosystem. It serves as a first-stage implant for remote control and follow-on intrusion activity. UNC3569 operations span government, education, technology, finance, and other sectors worldwide, with a concentration in East and Southeast Asia.
GRAYRABBIT supports process and command execution, interactive reverse shells, bidirectional file transfer, collection of system and user information, and loading of additional plugins. An analyzed 64-bit variant supports reflective plugin loading into memory and self-termination. Its command-and-control configuration and communications use RC4; observed communications run over raw TCP rather than TLS.
UNC3569 has deployed GRAYRABBIT through exploitation of CVE-2026-51990 in Tencent’s Sogou Input Method for Windows. The infection chain requires a victim to open a crafted custom-protocol link, which abuses unchecked command-line arguments and unrestricted navigation to load an attacker-controlled page in an outdated, unsandboxed Chromium component. Exploitation of CVE-2021-38003 then enables payload retrieval and DLL sideloading through a legitimate executable. Associated loaders use process-count-based anti-analysis checks, in-memory execution, and attempted self-deletion. Encrypted GRAYRABBIT payloads have also been distributed through GitHub and stored in cloud-hosted infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In the observed operation, UNC3569 used a known V8 flaw, CVE-2021-38003, to take control of the outdated browser component. | The exploit path was actively used to deploy GRAYRABBIT. The backdoor can contact its operators, collect system details, run commands, open an interactive command shell, move files, and load additional modules, giving intruders a flexible foothold after the initial click.
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
“The backdoor can ... run commands [and] open an interactive command shell.”
Command ID 1: Start an interactive reverse shell (CreateProcessA "cmd" with piped stdin/stdout/stderr).
“[GRAYRABBIT] is used to create a command shell remotely from the attacker, allowing for the uploading and downloading of files.”
The page contains a JavaScript exploit targeting any known V8 vulnerability from the last six years.
The encrypted payload blob is structured as a two-stage package: a position-independent shellcode stub followed by the XOR-encrypted GRAYRABBIT PE.
“One file was a DLL designed to spoof and hide inside a pirated copy of 7-Zip.”
It then deletes itself... and then marking the file for deletion. The file leaves the disk with no delete call in the behavior logs.
The payload is often obfuscated with an additional binary layer, including techniques such as XOR encoding, custom shellcode loaders... The shellcode decrypts the embedded PE payload using a simple XOR operation and then executes the payload.
“Running processes would be scrutinized for analysis methods in a sandboxed environment prior to deployment of the GRAYRABBIT.”
If it finds fewer than 50, it builds the wrong key and the payload turns to garbage. Automated malware-analysis systems tend to run few processes.
The loader reads the encrypted payload file from disk into memory, then runs an anti-sandbox gate before decrypting it... counting every running process... threshold of 50.
The system information beacon collects the machine's IPv4 address via GetAdaptersAddresses.
The DLL counts the processes running on the computer before it decrypts anything. If it finds fewer than 50, it builds the wrong key and the payload turns to garbage.
“The backdoor can contact its operators, collect system details, run commands, open an interactive command shell, move files, and load additional modules.”
“Running processes would be scrutinized for analysis methods in a sandboxed environment prior to deployment of the GRAYRABBIT.”
The GrayRabbit backdoor ... provides attackers with a reverse shell and can execute processes, load plugins, write data to the interactive shell, upload files to its command-and-control (C&C) server, collect system information, and terminate itself.
“GRAYRABBIT ... sends out requests for and receives information from a command server, encrypted by RC4 over port 443.”
The backdoor reaches its server at mail.uaiubifas[.]top on port 443, and the traffic there is plain TCP scrambled with RC4 rather than TLS.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular backdoor/RAT deployed through the Sogou Input Method one-click exploit chain. It provides command-and-control, system reconnaissance, command execution, interactive shell access, file transfer, and the ability to load additional modules.
A backdoor deployed by UNC3569 through a one-click exploit chain targeting Sogou Input Method on Windows. The chain abused unsafe protocol-link handling and an outdated embedded Chromium browser, then used DLL sideloading to load the payload. GRAYRABBIT supports command-and-control communication, system reconnaissance, command execution, interactive shell access, file transfer, and additional module loading. The reported C2 domain is mail.uaiubifas.top on port 443.
A backdoor used by UNC3569 that provides a reverse shell and supports process execution, plugin loading, interactive-shell data writes, file upload to its C2 server, system-information collection, and self-termination.
A modular backdoor associated with UNC3569. The analyzed 64-bit variant supports process execution, interactive reverse shells, file uploads and downloads, system and user information collection, and reflective loading of plugins into memory. It uses RC4-encoded command-and-control configuration. Attackers deploy it through a crafted Sogou URI that redirects an outdated, unsandboxed Chromium webview to an exploit page.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.