A zero-day flaw in Sogou Input Method—used by 455M people monthly—allowed Chinese threat actor UNC3569 to execute arbitrary code and install the GRAYRABBIT backdoor.
Anthropic’s September threat report describes how actors used Claude for reconnaissance, intrusion support, tool rebuilding and parallelized cyber operations.
The Chinese state-aligned group has moved well beyond telecoms into transportation and government, in what is now one of the broadest espionage campaigns on record.