Recently, Huorong Security published a technical report detailing its recent observation of a swiftly proliferating application engineered to lock browser homepages. Upon tracking the application's origin, it was discovered that the source traced back to Sogou Input Method. Leveraging the fundamental distribution module of the Shiply terminal, Sogou Input Method requests control configurations from the cloud and employs user profiling techniques to deliver targeted push notifications. The application's promotion module scans the user's device for antivirus software and subsequently forces changes to the homepage and default search engine settings of two widely-used browsers, Edge and Chrome, by tampering with their configuration files.