threat-intel
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
High
Summary
A cyber espionage campaign, dubbed Operation QUICSILVER, targeting Myanmar's government and IT sector is being conducted by a China-linked threat actor. The campaign uses a graduation ceremony lure to deliver a Go backdoor named QUICAgent, leveraging a multi-stage infection chain involving a malicious LNK file, a LOLBAS-like exploit via ftp.exe, and a custom Go-based backdoor. The campaign utilizes a kernel-mode driver, COOLCLIENT, to enhance stealth and evade detection.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
