Fake Graduation Invites Hide China-Linked Spy Tool in Myanmar

Researchers at Seqrite Labs say Operation QUICSILVER is using booby-trapped invitations to plant a new Go-based backdoor called QUICAgent on government and IT networks.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Formal graduation invitation cards arranged on a surface, with subtle digital artifacts or code elements emerging from the edges of the cards
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Seqrite Labs has named a new spying campaign against Myanmar targets Operation QUICSILVER.
  • Attackers send fake graduation ceremony invitations to trick staff into opening a malicious file.
  • The payload is a previously undocumented backdoor called QUICAgent, written in the Go programming language.
  • Government offices and IT companies in Myanmar are the confirmed targets.
  • Seqrite links the activity to a China-aligned hacking group with moderate confidence.

A hacking group with ties to China is quietly breaking into Myanmar government offices and technology firms by emailing fake graduation ceremony invitations, according to research from Seqrite Labs. Open one, and a hidden program called QUICAgent installs itself on the victim's machine, giving the attackers remote access to files and the ability to pull down more tools as needed.

This is classic espionage. Not ransomware, not theft for resale. The goal is to sit inside a target network and listen.

Who is being targeted?

Myanmar government bodies and IT companies inside the country. Seqrite hasn't published a victim count, but lures written in a style that would only make sense to insiders suggest the attackers already know exactly who they're writing to. That kind of tailored bait is a hallmark of state-linked spying, not the scattergun scam emails most office workers see.

What is QUICAgent?

QUICAgent is a backdoor: a hidden program that gives an outside attacker remote control of an infected machine. It's written in Go, a programming language from Google that compiles easily for Windows and Linux. That cross-platform reach makes the same tool deployable against different targets without rewriting it, which is why state-linked crews favour Go. Seqrite describes QUICAgent as previously undocumented, meaning it isn't already sitting in standard antivirus signature lists.

The campaign name QUICSILVER nods to the network protocol the malware uses to communicate with its operators: QUIC. QUIC is the same protocol modern browsers use to load pages from Google and YouTube quickly. Because legitimate web traffic uses it constantly, malware hiding inside QUIC is harder for corporate firewalls to flag.

Who is behind it?

Seqrite attributes Operation QUICSILVER to a China-nexus group with moderate confidence. That's analyst language for "the fingerprints point to China, but we're not certain." The firm hasn't publicly tied the activity to a named crew. Mustang Panda, which we reported on 17 August targeting Myanmar among other countries with a signed Windows rootkit concealing a backdoor, is one group active in the region, though Seqrite makes no such link here.

Myanmar has long drawn Chinese-aligned spying operations, given the shared border and Beijing's close interest in the ruling junta.

Campaign at a glance

Detail What Seqrite reports
Campaign name Operation QUICSILVER
Lure Graduation ceremony invitation
Malware QUICAgent (Go-based backdoor)
Targets Myanmar government and IT sector
Attribution China-nexus, moderate confidence

Should you worry?

If you work in a government office or IT firm anywhere in the region, treat unexpected invitation files with suspicion, even ones that look personal. A polished lure isn't proof the sender is real. When in doubt, call the person who supposedly sent it before opening the attachment.

Defenders should watch outbound QUIC traffic to unfamiliar servers and look for Go binaries running from user profile folders, a common staging location for this kind of tool.

Espionage tooling rarely stays contained. Once QUICAgent is documented and its signatures circulate, expect variants to appear outside Myanmar before long.

© 2026 Threat Vectr