Cybersecurity experts have discovered a cyberespionage campaign aimed at Myanmar that delivers a Go backdoor known as QUICAgent through invitation lures from graduation ceremonies.
According to Seqrite Labs, the effort, known as Operation QUICSILVER, is aimed at the government and IT sectors. There is a moderate degree of confidence that the activity was carried out by a China-nexus threat actor.
The assault was first noticed in April 2026, when it was seen to send a file called “HolidayNotice.pdf.exe” coupled with a fake Belgian-Myanmar public holiday calendar as a lure. A Virtual Hard Disk (VHD) file that initiates the infection chain is used by two following artifacts that were discovered in June and July of 2026.
A Windows Shortcut (LNK) that imitates a PDF document is included in the VHD file. When the victim opens the document, a fake PDF invitation to a graduation ceremony appears. It is written in Burmese and appears to be from the Information Technology and Cyber Security Department (ITCSD), which is part of Myanmar’s Ministry of Transport and Communications read more about Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
