Find notable cyber news and cases, enriched with sources, timelines, and signals.

Operation QUICSILVER Myanmar espionage campaign

Campaign
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

The Operation QUICSILVER espionage campaign is actively targeting Myanmar government and information technology sectors with graduation ceremony invitation lures that deliver the QUICAgent backdoor. The activity was first observed in April 2026 and later resurfaced with related artifacts in June and July 2026. The multi-stage chain combines a malicious LNK, ftp.exe abuse, and staged payload reconstruction, increasing the chance of stealthy compromise.

Related Happenings

ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites

Campaign
H score32 First: 19.08.2026 18:00 Last: 19.08.2026 18:00 Sources 1

About this happening: An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...

TA4922 Operation DragonReturn tax-themed phishing campaign

Campaign
H score32 First: 27.07.2026 13:51 Last: 27.07.2026 13:51 Sources 1

About this happening: A TA4922 phishing campaign has used tax-themed lures and attacker-controlled landing pages to deliver malware to Indian taxpayers and related finance personnel. Th...

GoSerpent malware activity targeting Southeast Asian entities

Malware Activity
H score26 First: 17.07.2026 11:46 Last: 17.07.2026 11:46 Sources 1

About this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...

Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors

Campaign
H score37 First: 03.07.2026 16:36 Last: 03.07.2026 16:36 Sources 1

About this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...

Mustang Panda Asia-Pacific and Japan CDN impersonation espionage campaign

Campaign
H score40 First: 14.05.2026 18:00 Last: 14.05.2026 18:00 Sources 1

About this happening: A Mustang Panda espionage campaign used CDN impersonation and DLL sideloading to target Asia-Pacific and Japan networks, extending from late September 2025 throu...

Timeline

  1. 24.08.2026 14:51 2 articles · 9h ago

    Operation QUICSILVER targets Myanmar government and IT sectors with QUICAgent

    Initial Disclosure

    Researchers identified Operation QUICSILVER as a cyber espionage campaign targeting Myanmar government and information technology sectors, delivered through graduation-ceremony and fabricated holiday-calendar lures to install the Go backdoor QUICAgent. The activity is assessed with moderate confidence to be the work of a China-nexus threat actor, was first observed in April 2026, and later reappeared with related VHD-based artifacts in June and July 2026. The infection chain uses a malicious LNK, abuses ftp.exe with the -s option, reconstructs payload material from header.doc and body.doc, retrieves a backend address through Cloudflare Workers, and communicates with its C2 over QUIC on UDP port 443.

    Show sources