China's President Xi Jinping speaks bilateral meeting

A China-linked espionage campaign used the encrypted protocol behind much of today's web browsing as a covert communications channel, exploiting a monitoring gap in enterprise and government networks that lack QUIC-aware inspection.

Cybersecurity researchers at Seqrite Labs disclosed the campaign, which they named Operation QUICSILVER, on August 17, 2026. The researchers documented a backdoor called QUICAgent that routed its command-and-control (C2) traffic over QUIC, the transport protocol used by HTTP/3, while using Cloudflare infrastructure to conceal the operators' servers.

The technique is not new. Security researchers have tracked C2 frameworks using QUIC since 2018. Because QUIC encrypts transport metadata, organisations relying on legacy TCP-based inspection tools may be unable to detect this class of communication.

The campaign targeted Myanmar government employees, particularly personnel from the Information Technology and Cyber Security Department (ITCSD) under the Ministry of Transport and Communications (MOTC), in at least three attack waves between April 2026 and the date of Seqrite's report.

Fake graduation invitation delivered as a VHD

The attack began with what appeared to be an official communication. A Virtual Hard Disk (VHD) file, normally used to mount disk images, was disguised as a JPEG image. When mounted, it displayed a formal graduation ceremony invitation written in Burmese, impersonating the ITCSD and MOTC and carrying what appeared to be an official ministry watermark.

The invitation referred to a graduation event scheduled for July 3, 2026, at the Assembly Hall of the MOTC headquarters in Naypyidaw. It listed two certificate programmes: Computer Repair & Maintenance, and Project Planning & Management for Software Development.

The visible document was not a PDF. The file named TrainingAnnouncement.pdf was actually a Windows shortcut (LNK) file carrying a PDF icon. Because Windows hides known file extensions by default, the victim saw only the filename and icon, with no .lnk extension to indicate a potential threat.

Three-stage infection chain

Seqrite said the attack used three stages designed to evade conventional endpoint detection.

Stage 1 — Abuse of a trusted Windows binary

Opening the LNK file launched ftp.exe, a Microsoft-signed Windows binary included with every Windows installation. The attackers used its -s: command-line option to execute a local script named _, a plain text file without an extension hidden inside the VHD, rather than connecting to an FTP server.

The technique is a documented Living Off the Land Binary and Script (LOLBAS) method listed under MITRE ATT&CK technique T1218. Since execution passed through a Microsoft-signed binary rather than an unfamiliar executable, signature-based endpoint tools had little basis for flagging it as malicious. Hive Security reported in a 2026 analysis that 79% of attack detections in 2024 involved no malware, reflecting the growing use of legitimate system tools in attacks.

Stage 2 — Reassembling the payload

While the graduation invitation appeared on screen, the script searched a hidden VHD directory for header.doc and body.doc. It combined the two files using the Windows copy /b command, a built-in binary concatenation tool, and saved the resulting payload as Windowsupdate.exe in the user's local application data directory.

Separating the payload into two document-like files meant that static analysis of either file alone was unlikely to produce an alert.

Stage 3 — QUICAgent

The reconstructed Windowsupdate.exe was a 64-bit Windows binary written in Go 1.20. Seqrite named the implant QUICAgent. Before contacting its operators, it introduced a random delay of 100 to 600 milliseconds and performed 1,000 rounds of SHA-256 hashing, apparently to exhaust the execution time available to automated malware sandboxes.

For persistence, the backdoor generated a temporary PowerShell script that created a shortcut named SystemIn.lnk in the current user's Windows Startup folder. The shortcut pointed to Windowsupdate.exe, causing the backdoor to run each time the user logged in.

QUIC and Cloudflare concealed the C2 traffic

QUICAgent's most distinctive feature was its C2 architecture.

Traditional monitoring focuses heavily on suspicious TCP connections to port 443. QUIC, standardised as IETF RFC 9000 in May 2021 and used by Cloudflare, Google and other major content-delivery networks for HTTP/3, runs over UDP on the same port.

Unlike TLS connections over TCP, QUIC encrypts transport metadata, including handshake details. This makes inspection more difficult for legacy firewalls and intrusion-detection systems. Active Countermeasures identified the gap in January 2025, noting that C2 frameworks exploit the limited ability of enterprise tools to parse QUIC traffic. Trellix's April 2026 CyberThreat Report also said the open-source AdaptixC2 framework had added QUIC support in 2025.

QUICAgent added another layer of concealment by using two Cloudflare Workers endpoints as a dead-drop resolver, rather than storing the C2 server address directly in the malware. On startup, it sent HTTP GET requests to appupdate[.]0cmds20cj2cdf8[.]workers[.]dev and regupdate[.]eamakfu49dc28wa[.]workers[.]dev.

The response from either endpoint contained the actual C2 hostname in plain text. The malware then constructed the final address and established a QUIC connection. Seqrite's dynamic analysis found that the Workers endpoint returned register[.]mediumser[.]com, which resolved to 104[.]64[.]211[.]22.

This created two layers of trusted-CDN cover. The initial traffic went to Cloudflare Workers subdomains and could resemble legitimate use of the service. The subsequent C2 connection used QUIC over UDP/443, a pattern that can also resemble legitimate CDN traffic.

The design allowed the operators to change the C2 domain simply by updating the Workers endpoint, without modifying the malware. Blocking register[.]mediumser[.]com would therefore not prevent a later campaign wave from using another hostname.

All C2 traffic was encrypted with RC4 using the hardcoded key MySecretEncryptionKey2025!@#$%. The backdoor also used a custom certificate-validation routine with an embedded self-signed certificate authority named "RAT CA" and the organisation name "RAT System", preventing man-in-the-middle inspection proxies from intercepting the channel.

Once connected, QUICAgent sent beacons every five seconds through HTTP/3 POST requests carrying RC4-encrypted JSON. It supported five operator commands: shell, set_heartbeat, upload, download and list_dir, providing extensive remote control of compromised systems.

Documents found in the VHD Recycle Bin

Some of the clearest clues came from files left in the VHD's Recycle Bin. Seqrite found deleted PDFs that appeared to be materials collected or staged by the attackers.

They included a concept note on the BIMSTEC Bay of Bengal Economic Dialogue and cooperation with Myanmar's Institute of Strategic and International Studies; an assessment of Malaysia's foreign-policy perspective on Myanmar's civil conflict marked "Secrt"; and two versions of a document titled "Inside Story of Trump's Visit to China", which impersonated official material from Myanmar's Ministry of Foreign Affairs and was marked "Confidential – For Official Use Only".

The documents were not active lures delivered to victims. However, their presence suggested an intelligence-gathering focus covering ASEAN diplomacy, BIMSTEC and ACMECS regional frameworks, UN-related communications, and Myanmar's bilateral relations with Western and Chinese parties.

Palo Alto Networks' Unit 42 has previously documented the China-linked Stately Taurus group targeting ASEAN entities, including Myanmar, with lures referring to Myanmar military ranks and ASEAN summit materials. The Diplomat reported in October 2025 that Salt Typhoon's attacks on US telecommunications networks followed years of reconnaissance in Southeast Asian infrastructure.

Possible link to Operation GriefLure

Seqrite linked Operation QUICSILVER to an earlier campaign with moderate confidence. The same builder hostname, desktop-stv6gg, appeared in malicious LNK files from both QUICSILVER and Operation GriefLure, a campaign disclosed by Seqrite in May 2026 that targeted senior Viettel Group executives in Vietnam and healthcare administrators in the Philippines.

Both campaigns used the same infection chain: a malicious LNK abusing ftp.exe to combine header.doc and body.doc into a second-stage payload. QUICSILVER used a new Go-based backdoor and different C2 infrastructure while retaining the shared builder artefact.

Seqrite assessed the activity as China-linked with moderate confidence, citing the Myanmar government targets, the intelligence profile suggested by the recovered documents and the shared techniques with GriefLure.

The campaign's three waves — a Belgian-Myanmar holiday calendar lure in April 2026, a graduation ceremony lure in June and an ACMECS regional-framework lure in July — each focused on a different diplomatic context. Seqrite said the pattern suggested systematic targeting of different parts of Myanmar's international engagement.

What defenders should do

Seqrite published indicators of compromise, MITRE ATT&CK mappings and product-detection signatures alongside its report.

The most urgent step for network defenders is to address the QUIC inspection gap, rather than blocking only the campaign's known indicators. Organisations that have not audited outbound QUIC traffic have a structural blind spot that can be reused by other threat actors.

Active Countermeasures recommends QUIC-aware inspection capable of parsing UDP/443 traffic and extracting JA3/JA4 fingerprints from QUIC handshakes. Where such inspection is not yet available, organisations can consider blocking outbound UDP/443 to unexpected or newly registered domains while allowing required Cloudflare, Google and other CDN IP ranges.

Endpoint teams should monitor ftp.exe spawning child processes, executing local scripts with the -s: option or making outbound connections. They should also alert on copy /b commands that combine files in temporary or application-data directories, and on LNK files with misleading extensions in recently mounted VHD or ISO images.

Threat hunters should search LNK metadata for desktop-stv6gg, check the SHA-256 hashes published by Seqrite and monitor DNS queries for register[.]mediumser[.]com and the two Cloudflare Workers subdomains: appupdate[.]0cmds20cj2cdf8[.]workers[.]dev and regupdate[.]eamakfu49dc28wa[.]workers[.]dev.

How Cloudflare Workers can hide malware servers

Cloudflare Workers is a serverless platform that runs code across Cloudflare's global edge network. Malware operators can use it as a dead-drop resolver by deploying a Workers function that returns the real C2 hostname while embedding only the Workers URL in the malware.

Because *.workers.dev subdomains are hosted on Cloudflare infrastructure, network tools may be unable to distinguish malicious resolver traffic from legitimate Workers use. Operators can also change the real C2 address by updating the Workers function, without modifying the malware. The technique, identified as MITRE ATT&CK T1102.001, was previously used by APT41 through services such as GitHub and Pastebin. Cloudflare Workers represents a newer variation that adds trusted-CDN cover.


Frequently Asked Questions

What is Operation QUICSILVER and who is behind it?

Operation QUICSILVER is a China-linked espionage campaign disclosed by Seqrite Labs on August 17, 2026. It targeted Myanmar government employees, particularly staff of the ITCSD under the Ministry of Transport and Communications, and deployed the Go-based QUICAgent backdoor. Seqrite attributed the activity to a China-linked cluster with moderate confidence based on shared builder artefacts with Operation GriefLure and an intelligence profile consistent with Chinese strategic interests in Southeast Asian diplomacy.

Why does QUIC make this attack difficult to detect?

QUIC runs over UDP on port 443, the same port used by HTTPS. It encrypts transport metadata, and many legacy firewalls and monitoring systems are not equipped to analyse UDP traffic in the same way as TCP/443. This creates a blind spot for QUIC-based C2 traffic. The recommended response is QUIC-aware inspection rather than blocking all UDP/443, which would disrupt legitimate browser and CDN traffic.

What is a LOLBAS attack?

Living Off the Land Binaries and Scripts attacks use legitimate, pre-installed and operating-system-signed tools for malicious purposes. In this campaign, the attackers used the Microsoft-signed ftp.exe binary and its -s: option to execute a local script instead of connecting to an FTP server. Detection therefore requires behavioural monitoring, including alerts for ftp.exe spawning unusual processes or executing local scripts.

What should organisations do now?

Network teams should confirm whether QUIC-aware inspection is available for outbound UDP/443. Endpoint teams should create behavioural detections for ftp.exe running local scripts and for copy /b combining files in temporary directories. Threat hunters should search for desktop-stv6gg in LNK metadata and check DNS logs for register[.]mediumser[.]com and the two Cloudflare Workers subdomains identified by Seqrite.

Originally published on Tech Times