
Operation QUICSILVER: China-Nexus Actor Targets Myanmar Government with New QUICAgent Backdoor
A sophisticated cyber espionage campaign, Operation QUICSILVER, is targeting Myanmar's government and IT sectors using graduation-themed lures to deploy the novel Go-based QUICAgent backdoor.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- High
- Actor Type:
- APT
- Geography:
- Southeast Asia
- Confidence:
- High Confidence
- Source:
- Seqrite Labs
- Read Time:
- 4 min
Executive Summary
On August 24, 2026, cybersecurity researchers at Seqrite Labs identified a new cyber espionage campaign dubbed 'Operation QUICSILVER.' This operation specifically targets government entities and information technology sectors within Myanmar. The campaign is characterized by the use of a sophisticated, previously undocumented backdoor written in the Go programming language, named QUICAgent. The primary objective appears to be long-term intelligence gathering and persistent access to sensitive government communications and infrastructure.
Threat Analysis
The infection vector for Operation QUICSILVER involves highly targeted spear-phishing emails. These emails utilize social engineering lures related to academic achievements, specifically masquerading as invitations to graduation ceremonies. This choice of lure suggests a focus on younger officials or those within the educational and administrative sectors of the Myanmar government. Once the recipient interacts with the malicious attachment or link, the QUICAgent payload is deployed, initiating the compromise of the host system. The campaign demonstrates a high level of preparation, with lures tailored to the specific cultural and administrative context of the target region.
Technical Details
QUICAgent is a Go-based backdoor, a choice that provides the attackers with cross-platform capabilities and makes analysis more complex due to the nature of Go's compiled binaries. The malware establishes persistence by modifying registry keys or creating scheduled tasks. It communicates with its Command and Control (C2) infrastructure using encrypted channels to evade network-based detection. Technical analysis reveals that QUICAgent is capable of file exfiltration, executing remote commands, and deploying additional second-stage modules. The use of Go allows the threat actors to rapidly iterate and deploy new versions of the agent with minimal changes to the core codebase, enhancing their operational agility.
Attribution Assessment
Based on the tactics, techniques, and procedures (TTPs) observed, researchers have attributed Operation QUICSILVER to a China-nexus threat actor with high confidence. The targeting of Myanmar aligns with historical Chinese strategic interests in the region, particularly concerning border security and economic corridors. Furthermore, the infrastructure used for C2 communication overlaps with known patterns associated with established Chinese Advanced Persistent Threat (APT) groups. The shift towards Go-based malware is also a growing trend among Asian-based espionage groups seeking to bypass traditional signature-based security solutions.
Implications
The success of Operation QUICSILVER poses a significant threat to the national security of Myanmar. By gaining a foothold in government and IT networks, the attackers can monitor internal policy discussions, track diplomatic correspondence, and potentially disrupt critical infrastructure. This level of access provides the sponsoring nation-state with a substantial information advantage in regional geopolitical negotiations and internal security matters. The focus on IT sectors also suggests a potential for supply-chain attacks or broader network lateral movement.
Recommendations
Encrygma recommends that organizations in the Southeast Asian region, particularly those in government and technology sectors, implement the following measures: 1. Enhance email filtering to detect and quarantine suspicious attachments, especially those using academic or official lures. 2. Deploy Endpoint Detection and Response (EDR) solutions capable of identifying anomalous Go-compiled binaries and unauthorized registry modifications. 3. Conduct targeted phishing awareness training for employees to recognize sophisticated social engineering. 4. Monitor for unusual outbound traffic to newly registered domains or known C2 infrastructure associated with China-nexus actors.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Iranian Intelligence Deploys Telegram-Controlled 'HEAVYGRAM' Malware to Target Global Dissidents

North Korean APT Targets South Korean Media and Automotive Sectors with New Linux Espionage Toolkit

