Security1 distinct publisher2 min readPublished
Seqrite's Myanmar campaign hides a Go backdoor's traffic in UDP 443, with a single HTTP request in the whole chain. The monitoring gap travels regardless of your threat model.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
There is exactly one HTTP request in the documented chain: a GET to two Cloudflare Workers domains that hands back the backend address, reported as 104.64.211[.]22 with port 443 appended [9]. That request is the part a proxy log can hold. Everything after it moves on a transport that TLS interception and TCP-443 handshake fingerprinting are not scoped to observe [1].
The implant is not quiet about it. Beacons leave every five seconds, each stamped with a per-host X-Agent-ID [11], which works out to 720 an hour and 17,280 a day from a single machine [2]. That regularity is the durable detection opportunity here, and it sits in flow records rather than content inspection, which makes it contingent on whether UDP flows are retained at all.
The host side avoids anything resembling a download. The June and July samples arrive inside a VHD [3]. The next stage is rebuilt from header.doc and body.doc in a hidden _rels directory using copy /b, according to Seqrite researchers Priya Patel and Kartik Jivani [7], so neither file on disk is the backdoor and the executable exists only after reassembly [3]. Persistence is a shortcut dropped in the user's Startup folder [12].
QUICAgent itself is thin: five commands covering shell execution, file transfer, directory browsing and changing the beacon interval [13]. Its anti-analysis is a random delay of 100 to 600 milliseconds plus 1,000 rounds of SHA-256 hashing, which Seqrite reads as an effort to exhaust sandbox execution limits [8]. The engineering that matters is not in the implant, it is in the choice of channel.
Attribution is moderate confidence [1], and the reporting supplied here is a single Hacker News write-up of Seqrite's research, so this rests on one vendor's telemetry until someone publishes overlapping indicators [5].
The same report carries Kaspersky's separate finding: Mustang Panda's updated COOLCLIENT, in the wild since 2022 [16], now shipping a signed kernel-mode driver called Msagent.sys that hides the process and shields its files and registry entries from inspection, sideloaded via PlugX [14], detected in intrusions across Myanmar, Mongolia, Pakistan and Russia [15]. Myanmar appears in both data sets [4]. Two China-nexus operations in the same country are buying stealth at different layers, one under the operating system's view and one under the network monitor's.
The transport decision cost the QUICSILVER operator a Go library. Closing the gap it exploits costs the defender either an egress policy on UDP 443 or QUIC-aware inspection, and the asymmetry is the reason it will keep working.
Ranked by verification strength, evidence, and original report placement.
Seqrite Labs assesses Operation QUICSILVER, a campaign targeting Myanmar government and information technology sectors, as the work of a China-nexus threat actor with moderate confidence.
The malware uses QUIC over UDP port 443 to communicate with the command-and-control server.
The activity was first observed in April 2026, delivering a file named "HolidayNotice.pdf.exe" alongside a lure that was a fabricated Belgian-Myanmar public holiday calendar.
Two subsequent artifacts, detected in June and July 2026, use a Virtual Hard Disk (VHD) file to activate the infection chain, with a Windows Shortcut (LNK) inside the VHD that mimics a PDF document.
Opening the shortcut displays a decoy PDF: an official graduation ceremony invitation written in Burmese, purporting to come from the Information Technology and Cyber Security Department (ITCSD) under Myanmar's Ministry of Transport and Communications.
While the decoy is displayed, the shortcut launches ftp.exe, a legitimate Microsoft-signed Windows binary, abusing its "-s" option to run commands stored in a local script file; Seqrite describes this as LOLBAS abuse.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed but single-vendor, single-publisher
The technical account is specific and internally consistent (named binaries, file paths, delay ranges, transport, beacon cadence, one C2 IP), and researchers are named. But every QUICSILVER detail traces to Seqrite Labs relayed by one publisher, the two supplied items are the same article, attribution is stated at moderate confidence, and no hashes or Workers domains are provided for independent verification.
Confirmed live activity, undisclosed scope
Real-world use is documented across three artifacts spanning April to July 2026 against a specific sector and country, and a related Kaspersky intrusion set spans four countries. However no victim numbers, successful-compromise counts, or telemetry volumes are supplied, so observed deployment is confirmed but narrow and unquantified.
Slightly overstated generalization
The underlying reporting is restrained and descriptive, and the QUIC-over-UDP-443 blind-spot logic follows directly from the reported chain. The mild overstatement is in generalizing from one moderate-confidence campaign with undisclosed victim scope to a broad claim about how most port-443 inspection is deployed, which no supplied source measures.
Vendor research disclosure incentives on both threads
Both threads are commercial security-vendor research: Seqrite Labs names and brands the campaign and implant it discovered, and Kaspersky discloses a previously undocumented driver. Naming rights and detection-capability positioning are standard incentives in such publications, and the relaying article does not disclose or discuss them.
Moderate: coherent technical detail, no corroboration
Confidence is limited by the absence of any second publisher or independent researcher in the cluster, duplicate source items inflating apparent coverage, an explicitly moderate-confidence attribution, and no disclosed victim scope. The specificity and internal consistency of the technical description keep it from falling lower.
build
A build step instead of a backend: 1,025 records, 8 locales, no runtime API1 distinct publisher
security
FTP welcome banners are the new dead drop, and that suits whoever reads netflow1 distinct publisher
build
Prisma v7 stops seeding for you, and the pooled URL will not finish the job1 distinct publisher
build
Nine locales, no middleware: route groups as a Cloudflare billing decision1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 24, 2026