China-Nexus Hackers Target Myanmar Diplomats With Government-Themed QUICAgent Malware Attacks
Brief
A China-nexus threat actor has launched a targeted malware campaign against Myanmar government and diplomatic personnel using fake government invitations and virtual hard disk (VHD) files.
Seqrite researchers named the activity Operation QUICSILVER and identified a custom Golang backdoor called QUICAgent.
The campaign uses Burmese-language decoy documents impersonating Myanmar’s Information Technology and Cyber Security Department under the Ministry of Transport and Communications.
One lure poses as an invitation to a graduation ceremony for government training programs, complete with an official-looking ministry seal.
Researchers believe the operation targets government and IT-sector personnel in Myanmar. Recovered deleted files also suggest the attackers may be interested in diplomatic matters involving ASEAN, BIMSTEC, UN meetings, Malaysia, China, and Myanmar’s foreign affairs.
