
Cybersecurity researchers have uncovered a cyber espionage campaign targeting government and information technology organizations in Myanmar. Named Operation QUICSILVER, the campaign uses fake graduation ceremony invitations to trick victims into opening malicious files. Researchers at Seqrite Labs assess with moderate confidence that the activity is linked to a China-nexus threat actor.
Fake Invitations Hide a Malware Attack
The campaign was first observed in April 2026 and later evolved to use Virtual Hard Disk (VHD) files. Inside these files is a Windows Shortcut (LNK) disguised as a PDF. When opened, victims see a fake Burmese-language graduation invitation supposedly issued by Myanmar’s Information Technology and Cyber Security Department. Meanwhile, the malicious shortcut secretly launches additional commands using Microsoft’s legitimate ftp.exe utility. The attack then reconstructs the next-stage payload from hidden files.
QUICAgent Connects to Remote Servers
The final payload is a Go-based backdoor called QUICAgent. It uses several techniques designed to avoid automated security analysis, including random delays and repeated SHA-256 calculations. After activation, the malware contacts a command-and-control server using the QUIC protocol over UDP port 443. It can execute commands, transfer files, browse directories and change its communication interval. The malware can also establish persistence by placing an LNK file in the Windows Startup folder.
Broader China-Linked Activity
The disclosure comes alongside reports of updated COOLCLIENT malware associated with the China-linked Mustang Panda group. Researchers found a new signed kernel-mode driver that increases the malware’s ability to remain hidden. COOLCLIENT has capabilities including credential theft, keylogging, clipboard collection and file management. The findings highlight how cyber espionage campaigns continue to combine social engineering, legitimate Windows tools and increasingly stealthy malware to target organizations across multiple countries.
Read the Original: Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Read Related Article: What Is A Career In Biotechnology Like?






