Fake Graduation Invites Hide China-Linked Spy Tool in Myanmar

Researchers at Seqrite Labs say Operation QUICSILVER is using booby-trapped invitations to plant a new Go-based backdoor called QUICAgent on government and IT networks.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial shot of a dimly lit university research server rack with cool blue indicator LEDs reflecting off polished floor tiles, faint green data
Share

Key points

  • Seqrite Labs has named a new spying campaign against Myanmar targets Operation QUICSILVER.
  • The attackers send fake graduation ceremony invitations to trick staff into opening a malicious file.
  • The payload is a previously undocumented backdoor called QUICAgent, written in the Go programming language.
  • Government offices and IT companies in Myanmar are the confirmed targets so far.
  • Seqrite links the activity to a China-aligned hacking group with moderate confidence.

A hacking group with ties to China is quietly breaking into Myanmar government offices and technology firms by emailing them fake graduation ceremony invitations, according to research from Seqrite Labs.

The researchers call the operation QUICSILVER. Open the invitation, and a hidden program called QUICAgent installs itself on the victim's computer. From there, the attackers can rummage through files, watch what staff are doing, and pull down more tools as they need them.

This is classic espionage work. Not ransomware, not theft for resale. The point is to sit inside a target network and listen.

Who is being targeted?

Myanmar government bodies and information technology companies inside the country. Seqrite has not published a victim count, but the lures (invitations written in a style that would only make sense to insiders) suggest the attackers already know who they are writing to.

That sort of tailored bait is a hallmark of state-linked spying rather than the scattergun scam emails most office workers see.

What is QUICAgent?

QUICAgent is a backdoor, meaning a hidden program that gives an outside attacker remote control of an infected machine. It was written in Go, a modern programming language made by Google that runs on Windows, Mac and Linux without much fuss. That makes life easier for the attackers and harder for defenders, because the same tool can be pointed at different systems.

Seqrite describes QUICAgent as previously undocumented. In plain terms: this is a fresh tool, not something already sitting in antivirus signature lists.

The name QUICSILVER is a nod to the network protocol the malware uses to phone home, called QUIC. QUIC is the same modern web protocol your browser uses to load Google and YouTube quickly. Because normal web traffic uses it too, malware hiding inside QUIC is harder for company firewalls to spot.

Who is behind it?

Seqrite attributes Operation QUICSILVER to a China-nexus group with moderate confidence. That is analyst language for "the fingerprints point to China, but we are not staking the house on it." The firm has not tied the activity to a named group such as Mustang Panda or APT41, at least not publicly.

Myanmar has long been a favourite target for Chinese-aligned spying crews, given the two countries' shared border, pipeline projects and Beijing's interest in the ruling junta's decisions.

Campaign at a glance

Detail What Seqrite reports
Campaign name Operation QUICSILVER
Lure Graduation ceremony invitation
Malware QUICAgent (Go-based backdoor)
Targets Myanmar government and IT sector
Attribution China-nexus, moderate confidence

What should ordinary staff take from this?

If you work in a government office or an IT firm anywhere in the region, treat unexpected invitation files with suspicion, even ones that look personal or flattering. A polished lure is not proof the sender is real. When in doubt, phone the person who supposedly sent it before opening the attachment.

The Hacker News first covered the Seqrite writeup. Defenders in the region should watch outbound QUIC traffic to unfamiliar servers and hunt for Go binaries running from user profile folders (a common staging spot for this kind of tool).

One more thing worth noting. Espionage tools rarely stay in one country. Once QUICAgent is documented, expect copycats and expect it to turn up outside Myanmar within months.

© 2026 Threat Vectr