Android has a security flaw
A China-linked spying group is tricking Myanmar government and technology staff into opening a file that looks like a photo. The file is really a virtual disk that quietly installs a hidden remote access program called QUICAgent on the victim's computer.
- Report priority
- Medium
- Targets
- Windows
How it works
- The campaign hides a virtual hard disk file behind a JPEG-style name.
- Opening it reveals what looks like a PDF invitation, which is actually a Windows shortcut that runs the built-in ftp.exe program to reassemble hidden files into the QUICAgent backdoor.
What to do
Affected organizations should look for unexpected files with a photo-style name that are unusually large or that turn out to be VHD or VHDX virtual disk files rather than real images.
Security teams should block or closely monitor VHD and VHDX mounting, watch for ftp.exe launching child processes from user profile folders, and treat unsolicited official-looking documents from these agencies with extra suspicion.
Technical details
Affected software: Windows
Seqrite traced a real campaign against Myanmar government and technology staff, called Operation QUICSILVER. Targets received a file named like a JPEG photo that was actually a virtual disk. Opening it showed what looked like a PDF graduation invitation from Myanmar's Information Technology and Cyber Security Department. That file was really a Windows shortcut, which ran the built-in ftp.exe program to open the decoy invitation while quietly rebuilding hidden files into the QUICAgent backdoor in the background.
QUICAgent is a custom 64-bit Go backdoor delivered inside a VHD disguised as a JPEG. A hidden LNK file, shown with a PDF icon, runs the signed Windows tool ftp.exe to open a decoy graduation invitation while quietly rebuilding hidden files into the payload. Before contacting operators, it sleeps and performs repeated hashing to stall sandbox analysis, then looks up its control server via a Cloudflare Workers page and connects over QUIC on UDP port 443 wrapped in RC4 encryption. Seqrite attributes the campaign, Operation QUICSILVER, to a China-nexus actor with moderate confidence, citing decoy content referencing ASEAN, BIMSTEC, UN meetings, and Myanmar diplomacy, plus related holiday and ACMECS-themed lures.
References
- seqrite.com · operation-quicsilver-china-nexus-actor-targets-myanmar-diplomats-via-vhd-delivered-go-backdoor Cyber Security News
- ppl-ai-file-upload.s3.amazonaws.com · China-Nexus-Hackers-Disguise-Malicious-VHD-as-JPEG-to-Deploy-QUICAgent-Backdoor.pdf Cyber Security News
- any.run · threat-intelligence-lookup Cyber Security News
- thehackernews.com · windrelay-android-malware-turns-victims.html TheHackerNews
- thehackernews.com · silkparasite-espionage-campaign-targets.html TheHackerNews
- thehackernews.com · evooo1bot-linux-botnet-exploits-known.html TheHackerNews
- infosecurity-magazine.com · fake-bank-of-america-phishing-scam Infosecurity Magazine
- gbhackers.com · balonx-phaas-steals-bank-otps GBHackers