Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor
Brief
Contents
- Introduction
- Key Targets
- Industries Affected
- Geographical focus
- Infection Chain
- Campaign Timeline
- Initial Findings
- Looking into the Decoy Document
- Technical Analysis
- Stage 1 – LNK-Based Initial Access
- Stage 2 – Split Payload Reconstruction via ftp Script
- Stage 3 – QUICAgent Implant – Go-Based Backdoor
- Infrastructure & Attribution
- Conclusion
- SEQRITE Protection
- Indicators of Compromise (IOCs)
- MITRE ATT&CK Mapping
Introduction
Seqrite APT Team has been tracking threat activity across the globe, with a focus on campaigns targeting different industries and regions. During our recent research, we found a campaign targeting Myanmar that uses a Burmese-language graduation ceremony invitation from Myanmar’s Information Technology and Cyber Security Department as lure.
The threat actor delivers the malware through a Virtual Hard Disk (VHD) file.
