In a recent cyber espionage campaign, dubbed Operation QUICSILVER, cybersecurity experts have identified a targeted attack against Myanmar’s government and IT sectors. The operation involves the deployment of a malicious backdoor known as QUICAgent, delivered through deceptive graduation ceremony invitations. Researchers from Seqrite Labs have linked the campaign to a China-associated threat group.
Operation QUICSILVER and Its Tactics
First detected in April 2026, the operation utilizes files disguised as a public holiday calendar to infiltrate systems. The attack chain begins with a file named “HolidayNotice.pdf.exe,” followed by a Virtual Hard Disk (VHD) file found in subsequent artifacts from June and July. This VHD file contains a Windows Shortcut (LNK) disguised as a PDF document.
When victims open the document, they see a fake graduation ceremony invitation purportedly from Myanmar’s Information Technology and Cyber Security Department. Meanwhile, the shortcut covertly executes “ftp.exe,” a legitimate Windows binary, to run commands from a local script. This script assembles a payload using two hidden document files, culminating in the deployment of QUICAgent.
Technical Details of the QUICAgent Backdoor
QUICAgent is a Go-based malware that evades detection by incorporating delays and executing multiple hashing operations. Once active, it retrieves the Command-and-Control (C2) server address dynamically via HTTP GET requests to Cloudflare domains. The malware employs the QUIC protocol over UDP port 443 for communication, transmitting beacons every five seconds.
Each compromised machine is assigned a unique identifier, and QUICAgent supports various commands, including file transfer and directory browsing. Persistence is achieved through an LNK file in the user’s startup folder, ensuring execution upon each login.
Links to the Mustang Panda Threat Actor
This disclosure arrives alongside reports of Mustang Panda, another China-linked actor, leveraging an updated backdoor called COOLCLIENT. This malware, first seen in 2022, now includes a kernel-mode driver that enhances stealth by concealing processes and files. COOLCLIENT is delivered using DLL sideloading and offers capabilities like keylogging and system reconnaissance.
The driver, identified by Kaspersky, has been detected in attacks across Myanmar, Mongolia, Pakistan, and Russia. It underscores the evolving threat landscape and the continuous adaptation of cyber espionage tactics by nation-state actors.
As these campaigns demonstrate sophisticated techniques and persistent targeting of governmental and technological sectors, cybersecurity vigilance remains paramount. The ongoing developments signal the need for robust defenses and comprehensive threat intelligence strategies.
