01Priority actionInventory Sogou Input Method installations and identify the versions and users associated with them.
02Priority actionConsult the vendor and Gen Threat Labs guidance for the applicable fix, mitigation, or removal decision.
03Priority actionReview endpoint and identity telemetry for crafted-link activity, unusual child processes, and backdoor-like persistence.
04Priority actionInvestigate potentially affected systems before simply reinstalling or deleting software, preserving relevant evidence where appropriate.
05Priority actionEnsure users and administrators receive targeted warnings about unexpected links and report suspected activity promptly.