Cybersecurity researchers have identified Operation QUICSILVER, a cyber espionage campaign primarily targeting government and information technology sectors in Myanmar. The campaign utilizes a Go-based backdoor known as QUICAgent, delivered through deceptive lures such as fake graduation ceremony invitations.
The attack begins with lures like a fabricated Belgian–Myanmar public holiday calendar or a graduation ceremony invitation from Myanmar's Ministry of Transport and Communications. These lures deliver a Virtual Hard Disk (VHD) file containing a Windows Shortcut (LNK) that mimics a PDF document. Upon opening, the shortcut stealthily launches a legitimate Microsoft-signed binary, "ftp.exe," to execute commands and reconstruct the QUICAgent payload.
QUICAgent is a Golang-based implant designed to perform sandbox evasion techniques, including random delays and SHA-256 hashing operations, to exhaust automated analysis tools. The malware establishes communication with a command-and-control (C2) server by dynamically retrieving its address from Cloudflare Workers domains and uses QUIC over UDP port 443 for encrypted communication. It transmits basic host information every five seconds.
Seqrite Labs assesses the activity to be the work of a China-nexus threat actor, with moderate confidence. This campaign represents a significant threat to Myanmar's critical infrastructure, demonstrating sophisticated techniques for initial access, evasion, and persistent control, underscoring the ongoing challenges of state-sponsored cyber espionage in the region.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A cyber espionage campaign, Operation QUICSILVER, is targeting Myanmar's government and IT sectors using a Go-based backdoor named QUICAgent. The campaign uses fake graduation ceremony invitations to deliver the malware, which employs sandbox evasion and QUIC for command-and-control communication. This activity highlights ongoing state-sponsored cyber threats against government infrastructure in Southeast Asia.