Actor Profile
Operation QUICSILVER is attributed with moderate confidence to a China-nexus threat actor conducting cyber espionage operations against Myanmar. The actor demonstrates sophisticated tradecraft, leveraging social engineering lures themed around government communications and employing multi-stage infection chains. First observed in April 2026, the actor targets government and information technology sectors, consistent with strategic intelligence collection objectives. The use of Burmese-language decoys and Myanmar-specific themes (graduation ceremonies, holiday calendars) indicates tailored targeting and operational planning focused on the region.
TTPs (Tactics, Techniques, Procedures)
The campaign employs a multi-stage infection chain beginning with malicious VHD files containing LNK shortcuts (T1204.002 - User Execution: Malicious File). The actor abuses ftp.exe, a legitimate Microsoft-signed binary, as a LOLBAS technique (T1218 - System Binary Proxy Execution) to execute commands from a local script file. The payload is reconstructed by combining header.doc and body.doc files using native Windows commands (T1027.002 - Obfuscated Files or Information: Software Packing). QUICAgent implements sandbox evasion via random delays and iterative SHA-256 hashing (T1497.003 - Virtualization/Sandbox Evasion: Time Based Evasion). C2 infrastructure is dynamically retrieved via HTTP GET requests to Cloudflare Workers domains, with QUIC over UDP port 443 used for communications (T1071.001 - Application Layer Protocol: Web Protocols, T1573 - Encrypted Channel). Persistence is achieved through LNK files in the Startup folder (T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder). The backdoor supports command execution (T1059), file operations (T1005 - Data from Local System), and directory enumeration (T1083 - File and Directory Discovery).
Targets & Patterns
The campaign specifically targets Myanmar's government and information technology sectors, reflecting strategic intelligence collection priorities aligned with China-nexus espionage objectives. The use of lures impersonating the Information Technology and Cyber Security Department (ITCSD) under Myanmar's Ministry of Transport and Communications demonstrates detailed knowledge of government structure and operational security awareness among targets. The IT sector targeting suggests interest in supply chain access or technology transfer intelligence. The Burmese-language decoys and culturally relevant themes (graduation ceremonies, public holidays) indicate careful victim profiling and localization efforts to maximize social engineering success rates. This targeting pattern aligns with broader China-nexus espionage campaigns observed across Southeast Asia focused on government entities and critical infrastructure sectors.
Historical Context
Operation QUICSILVER was first observed in April 2026 with a "HolidayNotice.pdf.exe" lure featuring a fabricated Belgian-Myanmar public holiday calendar. Subsequent waves in June and July 2026 evolved to use VHD files and graduation ceremony themes. The disclosure coincides with reporting on Mustang Panda (another China-linked actor) deploying an updated COOLCLIENT backdoor with kernel-mode driver capabilities across Myanmar, Mongolia, Pakistan, and Russia. COOLCLIENT, first detected in 2022, shares targeting overlap with Operation QUICSILVER in Myanmar, suggesting coordinated or parallel China-nexus espionage efforts in the region. The kernel-mode enhancements in COOLCLIENT (similar to TONESHELL) represent an escalation in stealth capabilities, while QUICAgent demonstrates innovation in C2 protocols (QUIC over UDP) and dynamic infrastructure resolution via Cloudflare Workers.
Defensive Recommendations
- Monitor for suspicious VHD file execution and LNK files masquerading as PDF documents, particularly those containing Burmese-language content or government-themed lures (T1204.002)
- Detect abuse of ftp.exe with the '-s' parameter via command-line logging (Sysmon Event ID 1, Windows Security Event 4688) and flag execution from unusual parent processes (T1218)
- Implement network monitoring for QUIC protocol traffic over UDP port 443 to non-standard destinations, and inspect HTTP GET requests to Cloudflare Workers domains for C2 resolution patterns (T1071.001)
- Alert on file reconstruction operations using 'copy /b' commands that combine files from hidden directories like '_rels', and monitor for SHA-256 hashing loops indicative of sandbox evasion (T1027.002, T1497.003)
- Audit Startup folder modifications and detect creation of LNK files in user Startup directories via registry and file system monitoring (T1547.001)
---
# Geopolitical Context
Geopolitical Context
Operation QUICSILVER represents a continuation of sustained cyber espionage activity against Myanmar, consistent with broader patterns of intelligence collection targeting Southeast Asian governments. The campaign, attributed with moderate confidence to a China-nexus threat actor, employs sophisticated social engineering using locally relevant lures—including graduation ceremony invitations from Myanmar's Information Technology and Cyber Security Department—to deploy the QUICAgent backdoor. The targeting of Myanmar's government and IT sectors aligns with strategic intelligence priorities in a country experiencing ongoing political instability since the 2021 military coup. The disclosure coincides with reporting on Mustang Panda, a known China-linked group, deploying enhanced COOLCLIENT backdoors with kernel-mode stealth capabilities across Myanmar, Mongolia, Pakistan, and Russia, suggesting coordinated or parallel collection efforts by multiple China-associated threat actors in the region.
State Actor Alignment
The campaign is attributed with moderate confidence to a China-nexus threat actor, though specific group attribution is not provided. The operational tradecraft—including multi-stage infection chains, LOLBAS abuse (ftp.exe), and custom Go-based tooling—is consistent with capabilities observed across multiple China-associated advanced persistent threat groups. The concurrent activity by Mustang Panda, a well-documented China-linked actor, deploying updated COOLCLIENT backdoors in Myanmar and neighboring states suggests a broader strategic interest in the region. Myanmar's geopolitical position, bordering China and hosting significant Chinese infrastructure investments, provides context for sustained intelligence collection operations. No public sanctions or formal attributions have been announced in connection with this specific campaign.
Business Impacty pro region
The targeting of Myanmar's government and IT infrastructure has direct implications for regional security in Southeast Asia, particularly given Myanmar's strategic location and ongoing internal conflict. Compromise of government networks could provide intelligence on Myanmar's military junta, ethnic armed organizations, and regional diplomatic positioning. The IT sector targeting raises supply chain concerns, as compromised service providers could enable lateral access to additional government and commercial entities across the region. The parallel Mustang Panda activity spanning Myanmar, Mongolia, Pakistan, and Russia indicates a broader Central and South Asian collection architecture. For ASEAN member states and regional partners, the campaign underscores persistent espionage risks from China-nexus actors and the need for enhanced defensive cooperation. European entities with diplomatic or commercial presence in Myanmar face elevated third-party risk from compromised government and IT service providers.
Forecast
If the China-nexus threat actor maintains operational security and continues refining social engineering lures tailored to Myanmar's bureaucratic processes, further compromises of government and IT sector targets are likely in the near term. Should Myanmar's military government lack resources or political will to enhance cybersecurity posture, the campaign may expand to additional ministries and state-owned enterprises. If regional intelligence sharing improves among ASEAN states and international partners, detection and disruption of related infrastructure may increase, potentially forcing operational adjustments by the threat actor. The deployment of kernel-mode rootkit capabilities by Mustang Panda suggests an escalation in stealth requirements; if this tradecraft proliferates to other China-nexus groups, detection and remediation will become significantly more challenging for under-resourced defenders in the region.
