Executive Summary
Seqrite has identified a new campaign, designated Operation QUICSILVER, attributed with moderate confidence to China-nexus threat actors. The campaign primarily targets Myanmar's government and IT sectors, utilizing lures related to diplomatic invitations and internal training programs to deliver malicious payloads via Virtual Hard Disk (VHD) files.
The infection chain is notably complex, beginning with a malicious LNK file that abuses the legitimate Windows binary 'ftp.exe' (LOLBAS) to execute a script that reconstructs the final Go-based backdoor from split components. This backdoor, named QUICAgent, features advanced techniques including sandbox evasion through SHA-256 hashing loops and the use of Cloudflare Workers as dead-drop resolvers for its C2 infrastructure.
The use of the QUIC protocol over UDP port 443 for command-and-control communication represents a sophisticated method for bypassing traditional network security monitoring that may only prioritize TCP-based traffic. The campaign demonstrates high operational maturity through its use of custom encryption and overlapping infrastructure with previous known activities like Operation GriefLure.
