Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs.
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs.
In context
- Topic: Ciberseguridad — Riesgo, identidad, respuesta a incidentes y cumplimiento.
- Source: The Hacker News
- Published: 24/08/2026
Continue reading at the original source →
Excerpt published automatically by the site radar. The full text belongs to its publisher and is linked above.
Why it matters
Most incidents that end up being expensive did not start with a sophisticated technique. They started with an account that should have been closed when somebody resigned, a server nobody knew was still on, or a broad permission granted to unblock someone that then stayed forever.
I separate technical risk from business risk, because they do not always match. A critical vulnerability in an isolated system matters less than a medium one in the system that issues invoices. Prioritising by severity without looking at where the money is is an expensive way to work hard and protect little.
What usually goes wrong
What I see fail most is the backup. It is configured, it runs every night, nobody checks it. The day you need to restore, it turns out it had been failing silently for four months, or that everything was backed up except exactly what was needed. A backup never restored is an assumption.
What to watch
- How it was communicated to customers and regulators, which is where reputational cost is decided.
- Whether third parties or suppliers were in the chain, because the perimeter now includes partners.
- How long it took to detect, usually the most revealing metric in the whole case.
How I read this entry
What I would review this very week is access: accounts belonging to people who left, permissions that grew without anyone trimming them, and shared credentials everybody swears do not exist. It is the least glamorous work and the one that cuts off the most attacks.
This entry is an excerpt from the original source, selected by the site radar. The commentary above is the site's own and does not belong to the cited publisher.
Living through this in your own team?
Open the chat and tell me how you're handling it. I'm interested in comparing notes.