
QUICAgent Uses ftp.exe LOLBAS and QUIC C2 to Target Myanmar ITCSD
Operation QUICSILVER delivered QUICAgent to Myanmar government targets using LOLBAS abuse and QUIC C2. Evidence points to a China-linked actor with moderate confidence but lacks independent technical attribution. The technique set aligns with Mustang Panda tradecraft and is likely to recur.
The infection chain begins with graduation ceremony lures in Burmese from the ITCSD. A VHD mounts an LNK that launches ftp.exe -s against a local script, concatenates the two document fragments via copy /b, then drops QUICAgent. The implant adds 100-600ms jitter and 1000 SHA-256 iterations before fetching its C2 address from Cloudflare Workers and switching to QUIC over UDP 443. Beacons repeat every five seconds with a unique X-Agent-ID. Persistence drops an LNK in the Startup folder. Seqrite's April-June-July 2026 artifacts show consistent use of the same two-stage reconstruction and Cloudflare fronting. This matches Mustang Panda's documented preference for signed binaries and multi-stage loaders seen in COOLCLIENT updates that later added kernel drivers. No independent packet captures confirm the 104.64.211[.]22 endpoint beyond Seqrite reporting. The campaign fits a pattern of China-nexus actors probing Myanmar's transport and communications ministry after 2021 infrastructure projects. QUIC over UDP 443 and dynamic C2 resolution reduce signature surface compared with prior HTTP implants. Expect follow-on activity to test the same loader against additional Burmese ministries or neighboring ASEAN IT contractors within 90 days.
Seqrite: QUICAgent variants using the same ftp.exe + document reconstruction loader will appear in two additional Myanmar ministries within 90 days
Sources (2)
- [1]Seqrite Labs Operation QUICSILVER Analysis(https://www.seqrite.com/blog/operation-quicsilver-quicagent/)
- [2]Kaspersky Mustang Panda COOLCLIENT Update(https://www.kaspersky.com/blog/mustang-panda-coolclient-kernel-driver/2026)