Executive Summary
Operation QUICSILVER is a cyber espionage campaign targeting Myanmar's government and IT sectors, attributed to a China-nexus threat actor with moderate confidence. First observed in April 2026, the campaign uses graduation ceremony invitation lures written in Burmese to deliver QUICAgent, a custom Go-based backdoor. The attack chain begins with malicious VHD files containing Windows shortcuts that masquerade as PDF documents, ultimately deploying the backdoor which communicates over QUIC protocol on UDP port 443 for command and control operations.
This incident highlights the continued targeting of Southeast Asian governments by suspected Chinese APT groups, representing the evolving use of legitimate protocols like QUIC to evade detection. The campaign demonstrates sophisticated social engineering tactics using culturally relevant lures and reflects the ongoing geopolitical tensions in the region through cyber means.
Why This Matters Now
This campaign represents the evolution of APT tactics using legitimate protocols like QUIC for stealth communications, while targeting critical government infrastructure during heightened geopolitical tensions in Southeast Asia, making detection and prevention more challenging for security teams.
Attack Path Analysis
Operation QUICSILVER began with spear-phishing emails containing VHD files with malicious LNK shortcuts disguised as graduation ceremony invitations targeting Myanmar government and IT sectors. The attackers used LOLBAS techniques with ftp.exe to reconstruct and execute the QUICAgent backdoor, which established persistent C2 communications via QUIC protocol over UDP 443. The Go-based implant provided file transfer, command execution, and directory browsing capabilities for ongoing espionage activities against critical infrastructure targets.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Spear-phishing emails delivered VHD files containing malicious LNK shortcuts disguised as PDF graduation ceremony invitations from Myanmar's ITCSD department
MITRE ATT&CK® Techniques
Spearphishing Attachment
Registry Run Keys / Startup Folder
Regsvr32
Deobfuscate/Decode Files or Information
Web Protocols
System Information Discovery
File and Directory Discovery
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
CISA Zero Trust Maturity Model 2.0 – Event Data Analysis
Control ID: DE.AE-3
PCI DSS 4.0 – External Penetration Testing
Control ID: 11.3.1
DORA – Testing of ICT Business Continuity Policy
Control ID: Article 11
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Segregation in Networks
Control ID: A.8.22
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Myanmar government agencies face direct cyber espionage targeting through QUICAgent backdoor, compromising sensitive state communications and administrative operations via sophisticated multi-stage attacks.
Information Technology/IT
IT sector organizations targeted by QUIC-based backdoors enabling lateral movement, command control, and data exfiltration through compromised network segmentation and encrypted traffic vulnerabilities.
Telecommunications
Ministry of Transport and Communications spoofing in attacks threatens telecommunications infrastructure through east-west traffic exploitation and inadequate egress security policy enforcement mechanisms.
Computer/Network Security
Cybersecurity firms must address advanced Go-based malware utilizing QUIC protocols, sandbox evasion techniques, and kernel-mode drivers bypassing traditional threat detection and anomaly response systems.
Sources
- Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoorhttps://thehackernews.com/2026/08/operation-quicsilver-targets-myanmar.htmlVerified
- Seqrite Labs Research Report on Operation QUICSILVERhttps://www.seqrite.com/blog/operation-quicsilver-myanmar-cyber-espionage/Verified
- Kaspersky Report on COOLCLIENT Driver Rootkithttps://securelist.com/honeymyte-coolclient-driver-rootkit/121028/Verified
- MITRE ATT&CK Framework - Living Off the Land Binarieshttps://attack.mitre.org/techniques/T1218/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained Operation QUICSILVER's lateral movement and data exfiltration capabilities through segmented access controls and egress policy enforcement. The attack's blast radius across Myanmar government infrastructure would likely have been significantly reduced through east-west traffic controls and workload isolation.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial malware execution would likely have been constrained to isolated network segments, limiting the attacker's ability to immediately access broader government infrastructure systems and reducing their initial foothold scope.
Control: Zero Trust Segmentation
Mitigation: QUICAgent payload reconstruction and execution would likely have been constrained by identity-aware access controls, limiting the malware's ability to establish persistent presence across government IT infrastructure and reducing privilege scope.
Control: East-West Traffic Security
Mitigation: Network reconnaissance and lateral expansion across Myanmar government systems would likely have been significantly constrained, limiting the attacker's ability to discover and access additional infrastructure components beyond the initial compromise point.
Control: Multicloud Visibility & Control
Mitigation: Dynamic C2 communications through Cloudflare Workers would likely have been detected and constrained through traffic analysis and policy enforcement, limiting the attacker's ability to maintain persistent command channels to government infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Systematic data collection and file transfer operations would likely have been constrained through egress policy controls, limiting the volume and scope of sensitive government information accessible for exfiltration from compromised infrastructure.
While some intelligence gathering may have occurred within segmented boundaries, the overall impact to Myanmar's critical infrastructure would likely have been substantially reduced through constrained lateral reach and limited data access scope.
Impact at a Glance
Affected Business Functions
- Government Administrative Services
- IT Infrastructure Management
- Cybersecurity Operations
- Official Communications
Estimated downtime: 7 days
Estimated loss: $500,000
Sensitive government communications, IT infrastructure details, internal documents from Myanmar's Information Technology and Cyber Security Department (ITCSD) and Ministry of Transport and Communications. Potential exposure of classified administrative data and cybersecurity protocols.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement between government IT systems and limit blast radius of compromised endpoints
- • Deploy Egress Security & Policy Enforcement to block unauthorized QUIC/UDP 443 communications to external Cloudflare Workers domains
- • Enable Multicloud Visibility & Control to detect anomalous C2 beacon patterns and suspicious automation from compromised government workloads
- • Activate Threat Detection & Anomaly Response capabilities to identify LOLBAS abuse patterns and covert payload reconstruction techniques
- • Establish Encrypted Traffic inspection to decrypt and analyze suspicious QUIC protocol communications bypassing traditional monitoring



