Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor
ID: 11071b57-5066-5974-ab01-885fb49fce46
STIX ID: report--11071b57-5066-5974-ab01-885fb49fce46
Feed Name: Seqrite Blog
Threat Score
Seqrite APT researchers describe Operation QUICSILVER, a targeted campaign against Myanmar government and IT personnel that uses VHD-disguised lures and a malicious LNK which abuses ftp.exe to reconstruct and execute a Go-based backdoor named QUICAgent; the implant retrieves C2 via Cloudflare Workers, communicates over QUIC/HTTP3 with RC4-encrypted payloads, achieves persistence via a Startup shortcut, and includes IOCs and MITRE ATT&CK mappings for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
