Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
After the victim clicks it, the shortcut calls the signed Windows utility ftp.exe and instructs it to run commands from a local script.
MITRE ATT&CK Mapping Tactic Technique ID Technique Name Initial Access T1566.001 Phishing: Spearphishing Attachment Execution T1204.002 User Execution: Malicious File T1059.001 Command and Scripting Interpreter
Persistence is achieved by setting up an LNK file in the current user's Windows Startup folder so that it's automatically executed the next time the user logs in to the system.
It also creates a shortcut in the current user’s Startup folder so the backdoor returns when that user signs in. | That apparent PDF is actually a Windows shortcut, known as an LNK file... After the victim clicks it, the shortcut calls the signed Windows utility ftp.exe and instructs it to run commands from a local script.
Persistence is achieved by setting up an LNK file in the current user's Windows Startup folder so that it's automatically executed the next time the user logs in to the system.
It also creates a shortcut in the current user’s Startup folder so the backdoor returns when that user signs in. | That apparent PDF is actually a Windows shortcut, known as an LNK file... After the victim clicks it, the shortcut calls the signed Windows utility ftp.exe and instructs it to run commands from a local script.
MITRE ATT&CK Mapping Tactic Technique ID Technique Name Initial Access T1566.001 Phishing: Spearphishing Attachment Execution T1204.002 User Execution: Malicious File T1059.001 Command and Scripting Interpreter T1218 System Binary Proxy Execution: ftp.exe Defense Evasion T1027.009 Obfuscated Files or Information
The initial file carries a JPEG-style name but is substantially larger than a normal photograph. When researchers checked its true format, it proved to be a VHD... That apparent PDF is actually a Windows shortcut, known as an LNK file.
Although it looked like a PDF document, it was actually a Windows shortcut (LNK) file using a PDF icon to appear legitimate.
MITRE ATT&CK Mapping Tactic Technique ID Technique Name Initial Access T1566.001 Phishing: Spearphishing Attachment Execution T1204.002 User Execution: Malicious File T1059.001 Command and Scripting Interpreter T1218 System Binary Proxy Execution: ftp.exe Defense Evasion T1027.009 Obfuscated Files or Information T1036.008 Masquerading: Masquerade File Type T1070.004 Indicator Removal: File Deletion
The "announcement" serves as a distraction while the shortcut file stealthily launches "ftp.exe," a legitimate Microsoft-signed Windows binary, and abuses its "-s" option to run commands stored in a local script file.
The payload is a Golang-based implant dubbed QUICAgent that performs sandbox evasion techniques before connecting to a command-and-control (C2) server. Specifically, it incorporates a random delay of 100-600 milliseconds and executes 1,000 iterations of SHA-256 hashing operations to exhaust automated sandbox execution time limits.
Once established, the implant collects the computer’s DNS name and the logged-in username...
Once established, the implant collects the computer’s DNS name and the logged-in username...
Once established, the implant collects the computer’s DNS name and the logged-in username, checks in every five seconds by default, and can run commands, move files, list directories, or change its check-in interval.
The payload is a Golang-based implant dubbed QUICAgent that performs sandbox evasion techniques before connecting to a command-and-control (C2) server. Specifically, it incorporates a random delay of 100-600 milliseconds and executes 1,000 iterations of SHA-256 hashing operations to exhaust automated sandbox execution time limits.
The malware uses QUIC over UDP port 443 to communicate with the C2 server. The initial beacon to the server also includes basic information about the compromised host.
the malware uses two Cloudflare Workers URLs to dynamically retrieve the backend server address.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go-based backdoor deployed through a malicious VHD-file infection chain in Operation QUICSILVER, a China-nexus espionage campaign targeting Myanmar.
A Go-based backdoor used in Operation QUICSILVER against Myanmar targets. It reconstructs from staged files, evades sandboxes with delay and repeated SHA-256 operations, retrieves its C2 dynamically via Cloudflare Workers, communicates over QUIC on UDP/443, beacons host information, executes commands, transfers files, browses directories, modifies beacon timing, and persists via an LNK in the Windows Startup folder.
Custom 64-bit Go backdoor used in a China-nexus espionage campaign. It uses anti-analysis delay via repeated hashing, retrieves active C2 via Cloudflare Workers, communicates over QUIC on UDP 443 with RC4 encryption, collects host/user information, executes commands, transfers and lists files, changes beacon interval, and persists via a Startup-folder shortcut.
A custom Go-based backdoor delivered in a multi-stage VHD/LNK infection chain. It performs sandbox evasion, resolves C2 dynamically via Cloudflare Workers, communicates with its C2 over HTTP/3 using QUIC on UDP/443, encrypts C2 traffic with RC4, collects host information, supports shell/file/directory tasking, and persists via a Startup-folder shortcut.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.