Executive Summary

Operation QUICSILVER is a cyber espionage campaign targeting Myanmar's government and IT sectors, attributed to a China-nexus threat actor with moderate confidence. First observed in April 2026, the campaign uses graduation ceremony invitation lures written in Burmese to deliver QUICAgent, a custom Go-based backdoor. The attack chain begins with malicious VHD files containing Windows shortcuts that masquerade as PDF documents, ultimately deploying the backdoor which communicates over QUIC protocol on UDP port 443 for command and control operations.

This incident highlights the continued targeting of Southeast Asian governments by suspected Chinese APT groups, representing the evolving use of legitimate protocols like QUIC to evade detection. The campaign demonstrates sophisticated social engineering tactics using culturally relevant lures and reflects the ongoing geopolitical tensions in the region through cyber means.

Why This Matters Now

This campaign represents the evolution of APT tactics using legitimate protocols like QUIC for stealth communications, while targeting critical government infrastructure during heightened geopolitical tensions in Southeast Asia, making detection and prevention more challenging for security teams.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The campaign uses QUIC protocol over UDP port 443 for command and control communications, which is less commonly monitored than traditional HTTP/HTTPS traffic, providing better evasion capabilities.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have constrained Operation QUICSILVER's lateral movement and data exfiltration capabilities through segmented access controls and egress policy enforcement. The attack's blast radius across Myanmar government infrastructure would likely have been significantly reduced through east-west traffic controls and workload isolation.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial malware execution would likely have been constrained to isolated network segments, limiting the attacker's ability to immediately access broader government infrastructure systems and reducing their initial foothold scope.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: QUICAgent payload reconstruction and execution would likely have been constrained by identity-aware access controls, limiting the malware's ability to establish persistent presence across government IT infrastructure and reducing privilege scope.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Network reconnaissance and lateral expansion across Myanmar government systems would likely have been significantly constrained, limiting the attacker's ability to discover and access additional infrastructure components beyond the initial compromise point.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Dynamic C2 communications through Cloudflare Workers would likely have been detected and constrained through traffic analysis and policy enforcement, limiting the attacker's ability to maintain persistent command channels to government infrastructure.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Systematic data collection and file transfer operations would likely have been constrained through egress policy controls, limiting the volume and scope of sensitive government information accessible for exfiltration from compromised infrastructure.

Impact (Mitigations)

While some intelligence gathering may have occurred within segmented boundaries, the overall impact to Myanmar's critical infrastructure would likely have been substantially reduced through constrained lateral reach and limited data access scope.

Impact at a Glance

Affected Business Functions

  • Government Administrative Services
  • IT Infrastructure Management
  • Cybersecurity Operations
  • Official Communications
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Sensitive government communications, IT infrastructure details, internal documents from Myanmar's Information Technology and Cyber Security Department (ITCSD) and Ministry of Transport and Communications. Potential exposure of classified administrative data and cybersecurity protocols.

Recommended Actions

  • Implement Zero Trust Segmentation to prevent lateral movement between government IT systems and limit blast radius of compromised endpoints
  • Deploy Egress Security & Policy Enforcement to block unauthorized QUIC/UDP 443 communications to external Cloudflare Workers domains
  • Enable Multicloud Visibility & Control to detect anomalous C2 beacon patterns and suspicious automation from compromised government workloads
  • Activate Threat Detection & Anomaly Response capabilities to identify LOLBAS abuse patterns and covert payload reconstruction techniques
  • Establish Encrypted Traffic inspection to decrypt and analyze suspicious QUIC protocol communications bypassing traditional monitoring

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image