Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished Updated

QUICSILVER runs its C2 over QUIC, and most port-443 inspection is scoped to TCP

Seqrite's Myanmar campaign hides a Go backdoor's traffic in UDP 443, with a single HTTP request in the whole chain. The monitoring gap travels regardless of your threat model.

The Watch · Security desk

How we use AISend a correction

What happened

  • Seqrite Labs attributes Operation QUICSILVER, aimed at Myanmar government and IT targets, to a China-nexus actor with moderate confidence.
  • The first sighting, in April 2026, paired a HolidayNotice.pdf.exe file with a fabricated Belgian-Myanmar public holiday calendar.
  • Later samples show a decoy graduation invitation in Burmese, branded to Myanmar's ITCSD under the Ministry of Transport and Communications.
  • Execution runs through Microsoft-signed ftp.exe, whose -s option is abused to run commands from a local script file.
  • The resulting Go backdoor, QUICAgent, talks to its controller using QUIC over UDP port 443.

Why it matters

  • constraint Inspection built on the assumption that 443 means TCP and TLS cannot cover this channel, so money already spent on interception buys no visibility into it.
  • cost The dependable signal is volumetric, which moves the bill to UDP flow record retention and query capacity rather than the TLS proxy most shops already run.
  • decision The lure is Myanmar-specific but the loader is portable, forcing a call on whether to detect signed-binary script execution even where the region is irrelevant.
  • exposure The reachable takedown surface belongs to Cloudflare's Workers namespace rather than the operator, and the resolved address is replaceable, so IP blocklists decay faster than the technique.

There is exactly one HTTP request in the documented chain: a GET to two Cloudflare Workers domains that hands back the backend address, reported as 104.64.211[.]22 with port 443 appended [9]. That request is the part a proxy log can hold. Everything after it moves on a transport that TLS interception and TCP-443 handshake fingerprinting are not scoped to observe [17].

The implant is not quiet about it. Beacons leave every five seconds, each stamped with a per-host X-Agent-ID [10], which works out to 720 an hour and 17,280 a day from a single machine [18]. That regularity is the durable detection opportunity here, and it sits in flow records rather than content inspection, which makes it contingent on whether UDP flows are retained at all.

The host side avoids anything resembling a download. The June and July samples arrive inside a VHD [4]. The next stage is rebuilt from header.doc and body.doc in a hidden _rels directory using copy /b, according to Seqrite researchers Priya Patel and Kartik Jivani [7], so neither file on disk is the backdoor and the executable exists only after reassembly [19]. Persistence is a shortcut dropped in the user's Startup folder [11].

QUICAgent itself is thin: five commands covering shell execution, file transfer, directory browsing and changing the beacon interval [12]. Its anti-analysis is a random delay of 100 to 600 milliseconds plus 1,000 rounds of SHA-256 hashing, which Seqrite reads as an effort to exhaust sandbox execution limits [8]. The engineering that matters is not in the implant, it is in the choice of channel.

Attribution is moderate confidence [1], and the reporting supplied here is a single Hacker News write-up of Seqrite's research, so this rests on one vendor's telemetry until someone publishes overlapping indicators [16].

The same report carries Kaspersky's separate finding: Mustang Panda's updated COOLCLIENT, in the wild since 2022 [15], now shipping a signed kernel-mode driver called Msagent.sys that hides the process and shields its files and registry entries from inspection, sideloaded via PlugX [13], detected in intrusions across Myanmar, Mongolia, Pakistan and Russia [14]. Myanmar appears in both data sets [20]. Two China-nexus operations in the same country are buying stealth at different layers, one under the operating system's view and one under the network monitor's.

The transport decision cost the QUICSILVER operator a Go library. Closing the gap it exploits costs the defender either an egress policy on UDP 443 or QUIC-aware inspection, and the asymmetry is the reason it will keep working.

What to watch

  • Whether a second vendor or a regional CERT publishes overlapping QUICSILVER indicators, which the reporting does not yet have.
  • Whether QUICAgent or the same ftp.exe and copy /b loader appears against targets outside Myanmar.
  • Whether the two Cloudflare Workers dead-drop domains are taken down, and where the operator moves the address lookup if they are.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence54
Adoption32
Hype gap+12
Incentives62
Confidence48
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Seqrite Labs assesses Operation QUICSILVER, a campaign targeting Myanmar government and information technology sectors, as the work of a China-nexus threat actor with moderate confidence.

    ReportedSupportedSource: Seqrite Labs, via The Hacker News2 sources— create a free account to open themView cited source
  2. [2]

    The malware uses QUIC over UDP port 443 to communicate with the command-and-control server.

  3. [3]

    The activity was first observed in April 2026, delivering a file named "HolidayNotice.pdf.exe" alongside a lure that was a fabricated Belgian-Myanmar public holiday calendar.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. thehackernews.com

    2 articles · August 24, 2026

    Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories