# Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor (QUICAgent)

> Seqrite Labs reports 'Operation QUICSILVER,' a China-nexus (moderate confidence) espionage campaign against Myanmar government and diplomatic personnel that lures victims with a Burmese-language graduation-ceremony invitation into mounting a VHD file disguised as a JPEG. The VHD contains a PDF-icon LNK that abuses ftp.exe to reconstruct and launch QUICAgent, a custom Go 1.20 backdoor that beacons over QUIC/HTTP3 with RC4-encrypted traffic and resolves fallback C2 via Cloudflare Workers dead-drop endpoints.

- **Published:** 2026-08-17T00:00:00Z
- **Last reviewed:** 2026-08-17T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2040
- **ID:** TL-2026-2040
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 19 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Seqrite Labs disclosed Operation QUICSILVER, a China-nexus (moderate confidence) cyber-espionage campaign targeting Myanmar government and diplomatic personnel, including staff of the Information Technology and Cyber Security Department (ITCSD) under the Ministry of Transport and Communications (MOTC), as well as embassy and NGO personnel. Recovered deleted documents from victim machines cover BIMSTEC affairs, Myanmar Institute of Strategic and International Studies (MISIS) collaboration, Malaysian foreign-policy assessments, and Ministry of Foreign Affairs material marked 'Confidential - For Official Use Only,' indicating a clear diplomatic/foreign-policy collection objective.

Initial access relies on a Burmese-language graduation-ceremony lure impersonating the ITCSD/MOTC (event date 3 July 2026, Assembly Hall, Office Building No. 2, MOTC, Naypyidaw; training topics: Computer Repair & Maintenance and Project Planning & Management for Software Development), alongside ACMECS (Ayeyawady-Chao Phraya-Mekong Economic Cooperation Strategy)-themed decoys. The lure delivers TrainingAnnouncement.jpg, which is in fact a Virtual Hard Disk (VHD) file. Mounting the VHD exposes TrainingAnnouncement.pdf.lnk, a Windows shortcut masquerading as a PDF (T1036.008) that, once opened, silently invokes the Microsoft-signed ftp.exe utility with the `-s:` flag against a locally dropped script named '_' (T1218, LOLBAS abuse). That script runs `copy /b` to concatenate two payload fragments, header.doc and body.doc, into Windowsupdate.exe in %LOCALAPPDATA% — a split-payload reconstruction technique (T1027.009) designed to defeat static and network-transit detection, since neither fragment alone resembles an executable. A decoy PDF (TrainingAnnouncement.pdf) is opened simultaneously to distract the victim.

Windowsupdate.exe is QUICAgent, a custom Go 1.20 backdoor (embedded build ID `VQ20YVf_9K_8cgCF_NX7/TKHb39wS9Mu5bek0tOPM/xNfDrnhseTXcWQEFyFKX/HlpR3WMRKM_BIA32YLDE`). It communicates with its C2 over QUIC transported on UDP/443 using HTTP/3, encrypting traffic with RC4 under a hardcoded key (`MySecretEncryptionKey2025!@#$%`) and validating the server via a custom VerifyPeerCertificate routine that checks for an embedded self-signed CA (subject 'RAT CA', organization 'RAT System'). Default beacon interval is 5 seconds and is remotely adjustable via a `set_heartbeat` command. Supported operator commands are `shell` (arbitrary command execution), `set_heartbeat`, `upload` (exfiltration), `download` (retrieval/staging of additional tooling), and `list_dir` (filesystem enumeration). Primary C2 resolves to register.mediumser.com (domain registered 20 March 2026 via NameSilo, delegated to Cloudflare DNS at kelly.ns.cloudflare.com), which pointed to 38.60.244.141 from 1-6 July 2026 before infrastructure moved to 104.64.211.22 from 7 July 2026 onward; maui-cocktailbar.com serves as a secondary/backup C2 domain. QUICAgent also resolves two Cloudflare Workers URLs (appupdate.0cmds20cj2cdf8.workers.dev and regupdate.eamakfu49dc28wa.workers.dev) as dead-drop resolvers (T1102.001), using a trusted, hard-to-block CDN-hosted service to locate or fall back to live C2 infrastructure.

For persistence, QUICAgent generates a PowerShell script (pattern `create_lnk_*.ps1`, T1059.001) that drops SystemIn.lnk into the current user's Startup folder, pointing back at Windowsupdate.exe so the backdoor auto-launches at every logon (T1547.001). Anti-analysis measures include a randomized 100-600ms execution delay and 1,000 iterations of SHA-256 hashing purely to burn sandbox time budgets (T1497.003), plus deletion of dropped intermediate artifacts to remove forensic traces (T1070.004). Two earlier delivery variants were identified: HolidayNotice.pdf.exe (April 2026, using a Belgian-Myanmar holiday-calendar lure) and ACMECS_Pillar_1.vhd (July 2026, reusing the same VHD/LNK chain with an ACMECS theme), showing the operators iterating lure content while keeping the loader mechanics constant.

Seqrite assesses China-nexus attribution with moderate confidence, driven by infrastructure and tooling overlap with 'Operation GriefLure' (Seqrite, published May 2026), a related China-nexus (moderate-to-high confidence) campaign against Vietnam's military-linked telecom sector and Philippine healthcare that used an identical LNK-abuses-ftp.exe infection chain reconstructing a payload from header.doc/body.doc fragments. Both campaigns share a builder hostname artifact, 'desktop-stv6gg', embedded in the malicious LNK files, while Operation QUICSILVER introduces a distinct Go-based backdoor (QUICAgent, versus GriefLure's sfsvc.exe payload) and wholly separate C2 infrastructure — consistent with a shared toolkit/builder used across multiple regional targets by the same or an affiliated China-nexus cluster. No CVE is associated with this campaign; compromise depends entirely on social engineering and LOLBAS abuse rather than a software vulnerability.

## MITRE ATT&CK

- T1566.001 Phishing: Spearphishing Attachment
- T1204.002 User Execution: Malicious File
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1218 System Binary Proxy Execution
- T1027.009 Obfuscated Files or Information: Embedded Payloads
- T1036.008 Masquerading: Masquerade File Type
- T1070.004 Indicator Removal: File Deletion
- T1497.003 Time Based Checks
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1082 System Information Discovery
- T1005 Data from Local System
- T1102.001 Web Service: Dead Drop Resolver
- T1071.001 Application Layer Protocol: Web Protocols
- T1573.001 Encrypted Channel: Symmetric Cryptography

## Sources

- [Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor](https://www.seqrite.com/blog/operation-quicsilver-china-nexus-actor-targets-myanmar-diplomats-via-vhd-delivered-go-backdoor/)
- [Operation GriefLure: Dissecting an APT Campaign Targeting Vietnam's Military Telecom & Philippine Healthcare](https://www.seqrite.com/blog/operation-grieflure-dissecting-an-apt-campaign-targeting-vietnams-military-telecom-philippine-healthcare/)
- [MITRE ATT&CK T1566.001 — Phishing: Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001/)
- [MITRE ATT&CK T1102.001 — Web Service: Dead Drop Resolver](https://attack.mitre.org/techniques/T1102/001/)
- [MITRE ATT&CK T1497.003 — Virtualization/Sandbox Evasion: Time Based Evasion](https://attack.mitre.org/techniques/T1497/003/)
- [MITRE ATT&CK T1036.008 — Masquerading: Masquerade File Type](https://attack.mitre.org/techniques/T1036/008/)
- [MITRE ATT&CK T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder](https://attack.mitre.org/techniques/T1547/001/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2040
