{"id":2506,"date":"2026-08-24T15:16:21","date_gmt":"2026-08-24T15:16:21","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2506"},"modified":"2026-08-24T15:16:21","modified_gmt":"2026-08-24T15:16:21","slug":"operation-quicsilver-targets-myanmar-government-and-it-with-quicagent-backdoor","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2506","title":{"rendered":"Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 24, 2026<\/span><\/span><span class=\"p-tags\">Cyber Espionage \/ Cyber Attack<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhAU29lFKKhJ4-37mroz3wn9p8YejZSqMG70AcTu4Z_FLB6hhof-kGO8-6KOfJcE5TXPvrziWpqDpLu_Mi64u8ilPMtdicwexovYdtmVQhhFOTlAeEamKEccbGQf4Y15ufNQRggwtyzLJy32qocItBHu4FX7FLYDYbnjBXuYMtflnNB4ttrzIdynMPcquxs\/s1700-e365\/silver.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent.<\/p>\n<p>The campaign, codenamed <strong><a href=\"https:\/\/www.seqrite.com\/blog\/operation-quicsilver-china-nexus-actor-targets-myanmar-diplomats-via-vhd-delivered-go-backdoor\/\" target=\"_blank\">Operation QUICSILVER<\/a><\/strong>, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate confidence.<\/p>\n<p>It was first observed in April 2026, when the attack was observed delivering a file named \u00abHolidayNotice.pdf.exe\u00bb along with a lure that was a fabricated Belgian\u2013Myanmar public holiday calendar. Two subsequent artifacts, each detected in June and July 2026, make use of a Virtual Hard Disk (VHD) file that activates the infection chain.<\/p>\n<p>Present within the VHD file is a Windows Shortcut (LNK) that mimics a PDF document. Opening the document displays a decoy PDF to the victim, an official graduation ceremony invitation that&#8217;s written in Burmese and purports to be from the Information Technology and Cyber Security Department (ITCSD), which operates under Myanmar&#8217;s Ministry of Transport and Communications.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-e100\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The \u00abannouncement\u00bb serves as a distraction while the shortcut file stealthily launches \u00abftp.exe,\u00bb a legitimate Microsoft-signed Windows binary, and abuses its \u00ab-s\u00bb option to run commands stored in a local script file.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>\u00abWhile the decoy is presented on the victim&#8217;s screen, the script searches for two document files, header.doc and body.doc, stored inside the hidden _rels directory,\u00bb security researchers Priya Patel and Kartik Jivani said. \u00abIt then combines these two files using the native Windows copy \/b command to reconstruct the next-stage payload.\u00bb<\/p>\n<p>The payload is a Golang-based implant dubbed QUICAgent that performs sandbox evasion techniques before connecting to a command-and-control (C2) server. Specifically, it incorporates a random delay of 100-600 milliseconds and executes 1,000 iterations of SHA-256 hashing operations to exhaust automated sandbox execution time limits.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJS0-Sem-0d5mmYgY-QmpxlorRSZUtS5jR5uCWA2XkuRE7uRWOE7RTurJ-6kiFx3Oy_zrCfLPjSKkAsejCNRQeJ5AKm33Sqv7Iekwi6kZOjNXF7nxkiJIVZhyST4KWKTHe3tb9Briw6qOUS2vvmtLAAcDj6TJgZY6jVApmEMpKvWYvKsSbrgCz9umJIa58\/s1700-e365\/seq.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJS0-Sem-0d5mmYgY-QmpxlorRSZUtS5jR5uCWA2XkuRE7uRWOE7RTurJ-6kiFx3Oy_zrCfLPjSKkAsejCNRQeJ5AKm33Sqv7Iekwi6kZOjNXF7nxkiJIVZhyST4KWKTHe3tb9Briw6qOUS2vvmtLAAcDj6TJgZY6jVApmEMpKvWYvKsSbrgCz9umJIa58\/s1700-e365\/seq.jpg\" alt=\"\" border=\"0\" data-original-height=\"371\" data-original-width=\"768\"\/><\/a><\/div>\n<p>The backend C2 server address is retrieved dynamically by sending an HTTP GET request to two Cloudflare Workers domains. Once the C2 address is obtained (\u00ab104.64.211[.]22\u00bb), it suffixes port 443 to the domain and constructs the final destination. The malware uses QUIC over UDP port 443 to communicate with the C2 server.<\/p>\n<p>The initial beacon to the server also includes basic information about the compromised host. The beacon is transmitted every five seconds, with each infected machine assigned a unique X-Agent-ID to identify the victim. QUICAgent is fairly basic in that it supports five commands to execute commands, transfer files, browse directories, and modify the beacon interval.<\/p>\n<p>Persistence is achieved by setting up an LNK file in the current user&#8217;s Windows Startup folder so that it&#8217;s automatically executed the next time the user logs in to the system.<\/p>\n<p>\u00abThe campaign uses a multi-stage infection chain that begins with a malicious LNK file, abuses ftp.exe as a LOLBAS to execute the next stage, reconstructs the payload from two fake document files, and finally deploys a custom Go-based backdoor that we have named QUICAgent,\u00bb the Indian cybersecurity company said.<\/p>\n<p>The disclosure comes as the China-linked Mustang Panda actor has been observed using an updated version of a known backdoor called COOLCLIENT that can deploy a signed kernel-mode driver (\u00abMsagent.sys\u00bb), similar to the kernel-mode enhancements identified in TONESHELL. The backdoor is assessed to be deployed via PlugX using DLL sideloading, a technique extensively abused by the hacking group.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>COOLCLIENT supports such a wide array of capabilities as keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-based extensions. It was first detected in the wild in 2022.<\/p>\n<p>\u00abThe driver enhances the malware&#8217;s stealth by hiding the COOLCLIENT process, protecting related files and registry entries, and preventing them from being inspected or modified,\u00bb Kaspersky <a href=\"https:\/\/securelist.com\/honeymyte-coolclient-driver-rootkit\/121028\/\" target=\"_blank\">said<\/a>, adding it detected the updated variant and its accompanying driver in intrusions across Myanmar, Mongolia, Pakistan, and Russia.<\/p>\n<p>\u00abWhile the overall execution flow remains consistent with previously documented COOLCLIENT variants, this sample introduces a previously undocumented kernel-mode driver that significantly expands the malware&#8217;s stealth capabilities.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 24, 2026Cyber Espionage \/ Cyber Attack Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2507,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[179,385,3143,287,3144,3142,78],"class_list":["post-2506","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-backdoor","tag-government","tag-myanmar","tag-operation","tag-quicagent","tag-quicsilver","tag-targets"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2506","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2506"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2506\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2507"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2506"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2506"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2506"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}