Graduation invites hide Go backdoor aimed at Myanmar officials

Seqrite Labs tracks Operation QUICSILVER, a China-nexus espionage push that delivers a QUIC-based Go implant to Myanmar targets.

CSBadmin
2 Min Read

Researchers at Seqrite Labs have flagged an espionage campaign targeting government and IT sector networks in Myanmar. Dubbed Operation QUICSILVER, it is attributed to a China-nexus actor with moderate confidence and has been active since April 2026.

The infection chain starts with a virtual hard disk file containing a Windows shortcut that mimics a PDF. Opening it shows a decoy graduation ceremony invitation written in Burmese and signed with the name of Myanmar’s Information Technology and Cyber Security Department. Behind the scenes, the shortcut abuses ftp.exe, a Microsoft-signed binary, to run commands that stitch two document files back together and release the payload.

The final stage is QUICAgent, a Golang backdoor that wastes sandbox time with thousands of SHA-256 hashing operations before phoning home. It retrieves its command server through Cloudflare Workers domains and talks to it over QUIC on UDP port 443, beaconing every five seconds. Persistence comes from a shortcut dropped in the user’s Startup folder.

Separately, Kaspersky reported an updated COOLCLIENT backdoor that deploys a signed kernel-mode driver called Msagent.sys to hide its process, files, and registry keys. The China-linked Mustang Panda group is assessed to distribute it through PlugX DLL sideloading, with intrusions observed in Myanmar, Mongolia, Pakistan, and Russia.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.