logo

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

ID: 4b21e3c2-a84f-5d3b-8f70-06a99f9b0c3d

STIX ID: report--4b21e3c2-a84f-5d3b-8f70-06a99f9b0c3d

Feed Name: The Hacker News

Threat Score
86/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: [email protected] (The Hacker News)

...
...

Researchers attributed a targeted cyber espionage campaign (Operation QUICSILVER) to a China-nexus actor targeting Myanmar government and IT sectors; attackers used VHD/LNK lures and LOLBAS abuse of ftp.exe to reconstruct and deploy a Go-based backdoor named QUICAgent that communicates to C2 via QUIC/UDP (notably retrieving the C2 via Cloudflare Workers and using 104.64.211.22:443), while related reporting highlights Mustang Panda’s use of COOLCLIENT with a signed kernel-mode driver to improve stealth.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.