Threat reportMalwareTL-2026-2040
Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor (QUICAgent)
Operation QUICSILVER (TL-2026-2040), also tracked as Operation QUICSILVER, is a high-severity malware campaign, first published 2026-08-17. It is linked to a China-nexus actor with medium confidence, affects Microsoft Windows (endpoint OS), maps to 14 MITRE ATT&CK techniques (T1005, T1027.009, T1036.008), and is covered by 9 detection rules and 19 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 19Indicators of compromise
Key facts for TL-2026-2040
- Threat ID
- TL-2026-2040
- Also known as
- Operation QUICSILVER
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government administration, diplomatic, non-governmental organizations
- Target regions
- myanmar, Southeast Asia
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in Operation QUICSILVER
Malware and tooling: QUICAgent
How Operation QUICSILVER works
Seqrite Labs reports 'Operation QUICSILVER,' a China-nexus (moderate confidence) espionage campaign against Myanmar government and diplomatic personnel that lures victims with a Burmese-language graduation-ceremony invitation into mounting a VHD file disguised as a JPEG. The VHD contains a PDF-icon LNK that abuses ftp.exe to reconstruct and launch QUICAgent, a custom Go 1.20 backdoor that beacons over QUIC/HTTP3 with RC4-encrypted traffic and resolves fallback C2 via Cloudflare Workers dead-drop endpoints.
Seqrite Labs disclosed Operation QUICSILVER, a China-nexus (moderate confidence) cyber-espionage campaign targeting Myanmar government and diplomatic personnel, including staff of the Information Technology and Cyber Security Department (ITCSD) under the Ministry of Transport and Communications (MOTC), as well as embassy and NGO personnel. Recovered deleted documents from victim machines cover BIMSTEC affairs, Myanmar Institute of Strategic and International Studies (MISIS) collaboration, Malaysian foreign-policy assessments, and Ministry of Foreign Affairs material marked 'Confidential - For Official Use Only,' indicating a clear diplomatic/foreign-policy collection objective.
Initial access relies on a Burmese-language graduation-ceremony lure impersonating the ITCSD/MOTC (event date 3 July 2026, Assembly Hall, Office Building No. 2, MOTC, Naypyidaw; training topics: Computer Repair & Maintenance and Project Planning & Management for Software Development), alongside ACMECS (Ayeyawady-Chao Phraya-Mekong Economic Cooperation Strategy)-themed decoys. The lure delivers TrainingAnnouncement.jpg, which is in fact a Virtual Hard Disk (VHD) file. Mounting the VHD exposes TrainingAnnouncement.pdf.lnk, a Windows shortcut masquerading as a PDF (T1036.008) that, once opened, silently invokes the Microsoft-signed ftp.exe utility with the `-s:` flag against a locally dropped script named '_' (T1218, LOLBAS abuse). That script runs `copy /b` to concatenate two payload fragments, header.doc and body.doc, into Windowsupdate.exe in %LOCALAPPDATA% — a split-payload reconstruction technique (T1027.009) designed to defeat static and network-transit detection, since neither fragment alone resembles an executable. A decoy PDF (TrainingAnnouncement.pdf) is opened simultaneously to distract the victim.
Windowsupdate.exe is QUICAgent, a custom Go 1.20 backdoor (embedded build ID `VQ20YVf_9K_8cgCF_NX7/TKHb39wS9Mu5bek0tOPM/xNfDrnhseTXcWQEFyFKX/HlpR3WMRKM_BIA32YLDE`). It communicates with its C2 over QUIC transported on UDP/443 using HTTP/3, encrypting traffic with RC4 under a hardcoded key (`MySecretEncryptionKey2025!@#$%`) and validating the server via a custom VerifyPeerCertificate routine that checks for an embedded self-signed CA (subject 'RAT CA', organization 'RAT System'). Default beacon interval is 5 seconds and is remotely adjustable via a `set_heartbeat` command. Supported operator commands are `shell` (arbitrary command execution), `set_heartbeat`, `upload` (exfiltration), `download` (retrieval/staging of additional tooling), and `list_dir` (filesystem enumeration). Primary C2 resolves to register.mediumser.com (domain registered 20 March 2026 via NameSilo, delegated to Cloudflare DNS at kelly.ns.cloudflare.com), which pointed to 38.60.244.141 from 1-6 July 2026 before infrastructure moved to 104.64.211.22 from 7 July 2026 onward; maui-cocktailbar.com serves as a secondary/backup C2 domain. QUICAgent also resolves two Cloudflare Workers URLs (appupdate.0cmds20cj2cdf8.workers.dev and regupdate.eamakfu49dc28wa.workers.dev) as dead-drop resolvers (T1102.001), using a trusted, hard-to-block CDN-hosted service to locate or fall back to live C2 infrastructure.
For persistence, QUICAgent generates a PowerShell script (pattern `create_lnk_*.ps1`, T1059.001) that drops SystemIn.lnk into the current user's Startup folder, pointing back at Windowsupdate.exe so the backdoor auto-launches at every logon (T1547.001). Anti-analysis measures include a randomized 100-600ms execution delay and 1,000 iterations of SHA-256 hashing purely to burn sandbox time budgets (T1497.003), plus deletion of dropped intermediate artifacts to remove forensic traces (T1070.004). Two earlier delivery variants were identified: HolidayNotice.pdf.exe (April 2026, using a Belgian-Myanmar holiday-calendar lure) and ACMECS_Pillar_1.vhd (July 2026, reusing the same VHD/LNK chain with an ACMECS theme), showing the operators iterating lure content while keeping the loader mechanics constant.
Seqrite assesses China-nexus attribution with moderate confidence, driven by infrastructure and tooling overlap with 'Operation GriefLure' (Seqrite, published May 2026), a related China-nexus (moderate-to-high confidence) campaign against Vietnam's military-linked telecom sector and Philippine healthcare that used an identical LNK-abuses-ftp.exe infection chain reconstructing a payload from header.doc/body.doc fragments. Both campaigns share a builder hostname artifact, 'desktop-stv6gg', embedded in the malicious LNK files, while Operation QUICSILVER introduces a distinct Go-based backdoor (QUICAgent, versus GriefLure's sfsvc.exe payload) and wholly separate C2 infrastructure — consistent with a shared toolkit/builder used across multiple regional targets by the same or an affiliated China-nexus cluster. No CVE is associated with this campaign; compromise depends entirely on social engineering and LOLBAS abuse rather than a software vulnerability.
MITRE ATT&CK techniques used in TL-2026-2040
Collection
Defense Evasion
T1027.009 Obfuscated Files or Information: Embedded Payloads; T1036.008 Masquerading: Masquerade File Type; T1070.004 Indicator Removal: File Deletion; T1497.003 Time Based Checks
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1102.001 Web Service: Dead Drop Resolver; T1573.001 Encrypted Channel: Symmetric Cryptography
Discovery
T1082 System Information Discovery
stealth
T1218 System Binary Proxy Execution
Persistence
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Initial Access
Affected products and versions in Operation QUICSILVER
- Microsoft — Windows (endpoint OS)
Vulnerable versions: Any Windows version supporting VHD mount, .lnk shortcut execution, and ftp.exe (no specific version dependency; social-engineering/LOLBAS-driven, not a software vulnerability)
Remediation for Operation QUICSILVER
Immediate actions
- Block network indicators: register.mediumser.com, maui-cocktailbar.com, 104.64.211.22, 38.60.244.141, and the two Cloudflare Workers URLs (appupdate.0cmds20cj2cdf8.workers.dev, regupdate.eamakfu49dc28wa.workers.dev) at DNS/proxy/firewall.
- Hunt for and quarantine the published SHA-256 hashes (TrainingAnnouncement.jpg, TrainingAnnouncement.pdf.lnk, Windowsupdate.exe, header.doc, body.doc, ACMECS_Pillar_1.vhd, HolidayNotice.pdf.exe) across endpoints and mail gateways.
- Hunt for SystemIn.lnk in user Startup folders and create_lnk_*.ps1 script artifacts as post-compromise indicators.
- Alert on ftp.exe spawned with a '-s:' argument pointing at a non-standard local script — this is not normal ftp.exe usage in most environments.
Workarounds
- Disable or restrict user-mode disk-image (VHD/VHDX) auto-mount handling via Group Policy for at-risk user populations.
- Block outbound QUIC/UDP-443 at the network perimeter for hosts that do not require it, forcing C2 fallback to more easily detected protocols.
Longer-term hardening
- Deploy EDR/behavioral detection for QUIC/HTTP3 traffic over UDP/443 to unfamiliar destinations, especially from endpoints not expected to use QUIC-based applications.
- Restrict or monitor VHD/VHDX mounting on user endpoints via Explorer, especially from email- or download-sourced files with non-VHD extensions.
- Enforce Attack Surface Reduction / application control rules blocking ftp.exe from being used as a script interpreter (LOLBAS abuse) outside of authorized administrative contexts.
- Deliver targeted phishing-awareness training to Myanmar government, MOTC, and diplomatic-mission staff on VHD/LNK-based lures given the ongoing campaign.
Timeline of Operation QUICSILVER
- Primary C2 domain register.mediumser.com registered via NameSilo, delegated to Cloudflare DNS (kelly.ns.cloudflare.com).
- Earlier delivery variant HolidayNotice.pdf.exe observed, using a Belgian-Myanmar holiday-calendar lure (exact day within April 2026 not disclosed by source).
- TrainingAnnouncement.jpg VHD-based delivery sample first observed (exact day within June 2026 not disclosed by source).
- Historical C2 IP 38.60.244.141 becomes active for register.mediumser.com.
- Date referenced in the graduation-ceremony lure document: Assembly Hall, Office Building No. 2, MOTC, Naypyidaw, 3:00 PM.
- Historical C2 IP 38.60.244.141 activity period ends.
- C2 infrastructure for register.mediumser.com pivots to current IP 104.64.211.22, active onward.
- ACMECS_Pillar_1.vhd delivery variant observed reusing the VHD/LNK infection chain with an ACMECS theme (exact day within July 2026 not disclosed by source).
- Seqrite Labs publishes Operation QUICSILVER research disclosing the campaign, IOCs, and full ATT&CK mapping.
Sources cited for Operation QUICSILVER
- Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor
- Operation GriefLure: Dissecting an APT Campaign Targeting Vietnam's Military Telecom & Philippine Healthcare
- MITRE ATT&CK T1566.001 — Phishing: Spearphishing Attachment
- MITRE ATT&CK T1102.001 — Web Service: Dead Drop Resolver
- MITRE ATT&CK T1497.003 — Virtualization/Sandbox Evasion: Time Based Evasion
- MITRE ATT&CK T1036.008 — Masquerading: Masquerade File Type
- MITRE ATT&CK T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Detection coverage for TL-2026-2040
As of 2026-08-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2040 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2040
1 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.