Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate confidence. It was first observed in April 2026, when the attack was observed delivering a file named "HolidayNotice.pdf.exe" along with a lure that was a fabricated Belgian–Myanmar public holiday calendar. Two subsequent artifacts, each detected in June and July 2026, make use of a Virtual Hard Disk (VHD) file that activates the infection chain. Present within the VHD file is a Windows Shortcut (LNK) that mimics a PDF document. Opening the document displays a decoy PDF to the victim, an official graduation ceremony invitation that's written in Burmese and purports to be from the Information Technology and Cyber Security Department (ITCSD), which operates under Myanmar's Ministry of Transport and Communications. The "announcement" serves as a distraction while the shortcut file stealthily launches "ftp.exe," a legitimate Microsoft-signed Windows binary, and abuses its "-s" option to run commands stored in a local script file. "While the decoy is presented on the victim's screen, the script searches for two document files, header.doc and body.doc, stored inside the hidden _rels directory," security researchers Priya Patel and Kartik Jivani said. "It then combines these two files using the native Windows copy /b command to reconstruct the next-stage payload." The payload is a Golang-based implant dubbed QUICAgent that performs sandbox evasion techniques before connecting to a command-and-control (C2) server. Specifically, it incorporates a random delay of 100-600 milliseconds and executes 1,000 iterations of SHA-256 hashing operations to exhaust automated sandbox execution time limits. The backend C2 server address is retrieved
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Read the original article
thehackernews.com →