← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 17, 2026 · 11:55via Malware.news

Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor

Brief

Contents

  • Introduction
  • Key Targets
  • Industries Affected
  • Geographical focus
  • Infection Chain
  • Campaign Timeline
  • Initial Findings
  • Looking into the Decoy Document
  • Technical Analysis
  • Stage 1 – LNK-Based Initial Access
  • Stage 2 – Split Payload Reconstruction via ftp Script
  • Stage 3 – QUICAgent Implant – Go-Based Backdoor
  • Infrastructure & Attribution
  • Conclusion
  • SEQRITE Protection
  • Indicators of Compromise (IOCs)
  • MITRE ATT&CK Mapping

Introduction

Seqrite APT Team has been tracking threat activity across the globe, with a focus on campaigns targeting different industries and regions. During our recent research, we found a campaign targeting Myanmar that uses a Burmese-language graduation ceremony invitation from Myanmar’s Information Technology and Cyber Security Department as lure.

The threat actor delivers the malware through a Virtual Hard Disk (VHD) file.

Read more on Malware.news