Seqrite reported that a suspected China-nexus threat actor targeted Myanmar government and diplomatic personnel in Operation QUICSILVER, using Burmese-language lures such as a graduation invitation impersonating Myanmar’s Information Technology and Cyber Security Department. The campaign delivered a .vhd file disguised as an image, containing a malicious .lnk file masquerading as a PDF to trigger execution. Researchers linked multiple 2026 samples to the activity, including HolidayNotice.pdf.exe, TrainingAnnouncement.jpg, and ACMECS_Pillar_1.vhd, indicating a focused intrusion set aimed primarily at Myanmar entities.
The infection chain abused ftp.exe to run a local script, rebuilt the malware from split files named header.doc and body.doc, and deployed a custom Go backdoor dubbed QUICAgent. The malware established persistence through a Startup-folder shortcut, resolved its real command-and-control server through Cloudflare Workers, and communicated over HTTP/3 using QUIC on UDP/443, with RC4 used to encrypt traffic. Seqrite said overlapping tradecraft, infrastructure artifacts, and victimology support a moderate-confidence assessment that the operation is linked to a China-nexus actor.

See the actors and campaigns active against you right now.
9 events from the most recent confirmed update back to the earliest known activity.
Historical DNS showed mediumser.com moving from 38.60.244.141 to 104.64.211.22, the IP later observed handling QUIC-based C2 traffic.
One Burmese-language lure impersonated Myanmar’s Information Technology and Cyber Security Department and referenced a graduation ceremony scheduled at the Ministry of Transport and Communications in Naypyidaw.
Seqrite observed a second VHD sample, ACMECS_Pillar_1.vhd, in July 2026. It shared the same infection chain, payload, and command-and-control infrastructure as the June sample.
Historical DNS records showed mediumser.com resolving to 38.60.244.141 during the first observed hosting period for the campaign infrastructure.
Seqrite observed a VHD-delivered sample named TrainingAnnouncement.jpg in June 2026 as part of the campaign targeting Myanmar government-related personnel. The VHD contained a disguised LNK that launched the QUICAgent infection chain.
Seqrite identified the earliest observed Operation QUICSILVER activity in April 2026 using a sample named HolidayNotice.pdf.exe. The lure was a fabricated Belgian–Myanmar public holiday calendar.
The domain mediumser.com, later used by QUICAgent command-and-control infrastructure, was registered via NameSilo and configured behind Cloudflare DNS.
A threat-research notice identified additional Operation QUICSILVER infrastructure, including maui-cocktailbar.com and two Cloudflare Workers URLs, and published SHA-256 indicators. It also reported that files recovered from the Recycle Bin provided attribution-relevant clues for the China-nexus campaign.
Seqrite publicly documented Operation QUICSILVER as a China-nexus campaign targeting Myanmar government personnel and described the QUICAgent Go backdoor, VHD/LNK delivery chain, Cloudflare Worker-based C2 resolution, and QUIC/HTTP3 communications.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 17 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
5 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourceseqrite.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.