Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cyber Espionage Targets Myanmar with QUICAgent Malware

Cyber Espionage Targets Myanmar with QUICAgent Malware

Posted on August 24, 2026 By CWS

In a recent cyber espionage campaign, dubbed Operation QUICSILVER, cybersecurity experts have identified a targeted attack against Myanmar’s government and IT sectors. The operation involves the deployment of a malicious backdoor known as QUICAgent, delivered through deceptive graduation ceremony invitations. Researchers from Seqrite Labs have linked the campaign to a China-associated threat group.

Operation QUICSILVER and Its Tactics

First detected in April 2026, the operation utilizes files disguised as a public holiday calendar to infiltrate systems. The attack chain begins with a file named “HolidayNotice.pdf.exe,” followed by a Virtual Hard Disk (VHD) file found in subsequent artifacts from June and July. This VHD file contains a Windows Shortcut (LNK) disguised as a PDF document.

When victims open the document, they see a fake graduation ceremony invitation purportedly from Myanmar’s Information Technology and Cyber Security Department. Meanwhile, the shortcut covertly executes “ftp.exe,” a legitimate Windows binary, to run commands from a local script. This script assembles a payload using two hidden document files, culminating in the deployment of QUICAgent.

Technical Details of the QUICAgent Backdoor

QUICAgent is a Go-based malware that evades detection by incorporating delays and executing multiple hashing operations. Once active, it retrieves the Command-and-Control (C2) server address dynamically via HTTP GET requests to Cloudflare domains. The malware employs the QUIC protocol over UDP port 443 for communication, transmitting beacons every five seconds.

Each compromised machine is assigned a unique identifier, and QUICAgent supports various commands, including file transfer and directory browsing. Persistence is achieved through an LNK file in the user’s startup folder, ensuring execution upon each login.

Links to the Mustang Panda Threat Actor

This disclosure arrives alongside reports of Mustang Panda, another China-linked actor, leveraging an updated backdoor called COOLCLIENT. This malware, first seen in 2022, now includes a kernel-mode driver that enhances stealth by concealing processes and files. COOLCLIENT is delivered using DLL sideloading and offers capabilities like keylogging and system reconnaissance.

The driver, identified by Kaspersky, has been detected in attacks across Myanmar, Mongolia, Pakistan, and Russia. It underscores the evolving threat landscape and the continuous adaptation of cyber espionage tactics by nation-state actors.

As these campaigns demonstrate sophisticated techniques and persistent targeting of governmental and technological sectors, cybersecurity vigilance remains paramount. The ongoing developments signal the need for robust defenses and comprehensive threat intelligence strategies.

The Hacker News Tags:China-nexus, CoolClient, cyber espionage, Cybersecurity, Go backdoor, Mustang Panda, Myanmar, QUICAgent, QUICSILVER, Seqrite Labs

Post navigation

Previous Post: AmnesiaStealer Threatens Mac Security with Hidden Browser Control
Next Post: Enhancing Application Security in the AI Age

Related Posts

ZAST.AI Secures M to Enhance AI-Driven Code Security ZAST.AI Secures $6M to Enhance AI-Driven Code Security The Hacker News
Winning Against AI-Based Attacks Requires a Combined Defensive Approach Winning Against AI-Based Attacks Requires a Combined Defensive Approach The Hacker News
HOOK Android Trojan Adds Ransomware Overlays, Expands to 107 Remote Commands HOOK Android Trojan Adds Ransomware Overlays, Expands to 107 Remote Commands The Hacker News
Hacktivist Surge: 149 DDoS Attacks Across 16 Nations Hacktivist Surge: 149 DDoS Attacks Across 16 Nations The Hacker News
Microsoft Unveils Phishing Scheme Affecting Thousands Globally Microsoft Unveils Phishing Scheme Affecting Thousands Globally The Hacker News
Taiwan NSB Alerts Public on Data Risks from TikTok, Weibo, and RedNote Over China Ties Taiwan NSB Alerts Public on Data Risks from TikTok, Weibo, and RedNote Over China Ties The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Isolated-vm Vulnerability Risks JavaScript Security
  • TikTok Settles $400 Million Privacy Case with DOJ
  • AI Threats and Security Vulnerabilities Highlighted This Week
  • Android Malware Targets Car Screens Through Updates
  • Enhancing Application Security in the AI Age

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Isolated-vm Vulnerability Risks JavaScript Security
  • TikTok Settles $400 Million Privacy Case with DOJ
  • AI Threats and Security Vulnerabilities Highlighted This Week
  • Android Malware Targets Car Screens Through Updates
  • Enhancing Application Security in the AI Age

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark