Operation QUICSILVER Myanmar espionage campaign
Campaign
Summary
Hide ▲
Show ▼
The Operation QUICSILVER espionage campaign is actively targeting Myanmar government and information technology sectors with graduation ceremony invitation lures that deliver the QUICAgent backdoor. The activity was first observed in April 2026 and later resurfaced with related artifacts in June and July 2026. The multi-stage chain combines a malicious LNK, ftp.exe abuse, and staged payload reconstruction, increasing the chance of stealthy compromise.
Related Happenings
E4del and PINHOLE Windows RAT activity via FTP-banner dead-drop resolvers
Malware Activity
H score29
First: 21.08.2026 14:00
Last: 21.08.2026 14:00
Sources 1
About this happening:
SOCRadar reported a new campaign abusing FTP banners as dead drop resolvers to deliver two previously unreported Windows RATs, E4del and PINHOLE. The activ...
E4del and PINHOLE Windows RAT activity via FTP-banner dead-drop resolvers
Malware ActivityAbout this happening: SOCRadar reported a new campaign abusing FTP banners as dead drop resolvers to deliver two previously unreported Windows RATs, E4del and PINHOLE. The activ...
FTP-banner dead-drop resolver malware delivery campaign
Campaign
H score44
First: 21.08.2026 14:00
Last: 21.08.2026 14:00
Sources 1
About this happening:
A campaign is using FTP banners as dead-drop resolvers to deliver the E4del and PINHOLE Windows RATs, creating a command-delivery path that hides instructions...
FTP-banner dead-drop resolver malware delivery campaign
CampaignAbout this happening: A campaign is using FTP banners as dead-drop resolvers to deliver the E4del and PINHOLE Windows RATs, creating a command-delivery path that hides instructions...
ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
Campaign
H score32
First: 19.08.2026 18:00
Last: 19.08.2026 18:00
Sources 1
About this happening:
An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...
ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
CampaignAbout this happening: An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...
TA4922 Operation DragonReturn tax-themed phishing campaign
Campaign
H score32
First: 27.07.2026 13:51
Last: 27.07.2026 13:51
Sources 1
About this happening:
A TA4922 phishing campaign has used tax-themed lures and attacker-controlled landing pages to deliver malware to Indian taxpayers and related finance personnel. Th...
TA4922 Operation DragonReturn tax-themed phishing campaign
CampaignAbout this happening: A TA4922 phishing campaign has used tax-themed lures and attacker-controlled landing pages to deliver malware to Indian taxpayers and related finance personnel. Th...
GoSerpent malware activity targeting Southeast Asian entities
Malware Activity
H score26
First: 17.07.2026 11:46
Last: 17.07.2026 11:46
Sources 1
About this happening:
GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
GoSerpent malware activity targeting Southeast Asian entities
Malware ActivityAbout this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
Timeline
-
24.08.2026 14:51 2 articles · 13d ago
Operation QUICSILVER targets Myanmar government and IT sectors with QUICAgent
Initial DisclosureResearchers identified Operation QUICSILVER as a cyber espionage campaign targeting Myanmar government and information technology sectors, delivered through graduation-ceremony and fabricated holiday-calendar lures to install the Go backdoor QUICAgent. The activity is assessed with moderate confidence to be the work of a China-nexus threat actor, was first observed in April 2026, and later reappeared with related VHD-based artifacts in June and July 2026. The infection chain uses a malicious LNK, abuses ftp.exe with the -s option, reconstructs payload material from header.doc and body.doc, retrieves a backend address through Cloudflare Workers, and communicates with its C2 over QUIC on UDP port 443.
Show sources
- Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor — thehackernews.com — 24.08.2026 14:51
- Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor — thehackernews.com — 24.08.2026 14:51