A zero-day flaw in Sogou Input Method—used by 455M people monthly—allowed Chinese threat actor UNC3569 to execute arbitrary code and install the GRAYRABBIT backdoor.
The Chinese state-aligned group has moved well beyond telecoms into transportation and government, in what is now one of the broadest espionage campaigns on record.