China-Nexus Hackers Disguise Malicious VHD as JPEG to Deploy QUICAgent Backdoor

China-Nexus Hackers Disguise Malicious VHD as JPEG to Deploy QUICAgent Backdoor

A China-nexus cyber espionage campaign is using a convincing visual trick to reach Myanmar government and technology personnel.

The attackers present a virtual hard disk, or VHD, as an ordinary JPEG image, betting that recipients will not question a familiar file extension before opening it.

Inside the mounted disk is what appears to be an official Burmese-language graduation invitation from Myanmar’s Information Technology and Cyber Security Department.

The document offers a believable reason to click, while hidden components quietly begin installing a remote access tool called QUICAgent.

Analysts at Seqrite identified the activity as Operation QUICSILVER and assess its China-nexus connection with moderate confidence.

Related lures included a fabricated holiday notice and an ACMECS-themed file, suggesting interest in government and diplomatic personnel. The operation combines routine Windows features with social engineering.

A false image file, document-shaped shortcut, and legitimate system program can make a dangerous chain look harmless, showing why malicious LNK file campaigns remain a practical risk for targeted organisations.

Infection Chain (Source - Seqrite)
Infection Chain (Source – Seqrite)

Seqrite said in a report shared with Cyber Security News (CSN) that the actors left deleted material in the virtual disk’s Recycle Bin.

The files were not part of the delivered lure, but references to ASEAN, BIMSTEC, United Nations meetings and Myanmar diplomacy provide context on the operation’s likely interests.

China-Nexus Hackers Disguise Malicious VHD as JPEG

The initial file carries a JPEG-style name but is substantially larger than a normal photograph. When researchers checked its true format, it proved to be a VHD.

Opening it exposes a single apparent PDF, complete with a PDF icon, rather than revealing the virtual disk’s hidden contents.

That apparent PDF is actually a Windows shortcut, known as an LNK file. Windows commonly suppresses familiar extensions, so a recipient sees a believable document name instead of the final shortcut suffix.

This tactic mirrors other cases where weaponized document shortcut files turned a trusted-looking attachment into the first step of an intrusion.

Decoy Document (Source - Seqrite)
Decoy Document (Source – Seqrite)

After the victim clicks it, the shortcut calls the signed Windows utility ftp.exe and instructs it to run commands from a local script.

The script opens the decoy invitation in the foreground, then joins two concealed files masquerading as documents to rebuild and start the actual payload in the user’s local application-data folder.

The lesson is simple: file icons and displayed extensions are not reliable proof of a file’s type.

Teams should scrutinise unexpected disk-image files, restrict or closely monitor VHD mounting where it is not needed, and train staff to treat unsolicited documents with extra care, particularly if the subject claims to be official or time-sensitive.

QUICAgent Uses Cloud Services for Direction

QUICAgent is a custom 64-bit Go backdoor that pauses briefly and performs repeated hashing work before it contacts its operators.

That behaviour is designed to consume the limited time available in automated analysis environments, helping the implant avoid quick inspection before moving to the next stage.

Rather than keeping its final command server directly in the malware, QUICAgent queries Cloudflare Workers pages for the active address.

It then communicates over QUIC on UDP port 443 and wraps its traffic with RC4 encryption.

Infrastructure & Attribution (Source - Seqrite)
Infrastructure & Attribution (Source – Seqrite)

This layered arrangement makes infrastructure changes easier and can blur malicious traffic among routine encrypted web connections, much like the trend in backdoors using trusted services.

Once established, the implant collects the computer’s DNS name and the logged-in username, checks in every five seconds by default, and can run commands, move files, list directories, or change its check-in interval.

It also creates a shortcut in the current user’s Startup folder so the backdoor returns when that user signs in.

Security teams should hunt for suspicious shortcut creation in Startup folders, unusual ftp.exe activity, and outbound QUIC connections from endpoints that have no business reason to use them.

Correlating those signals with Chinese espionage backdoor activity can help investigators distinguish an isolated alert from a broader targeted campaign. The indicators below can support blocking, hunting, and retrospective review.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
SHA-25626f735cbbb1257be94e6d01656a35bf66a8ae9c34868548d69ec5cb588f9f916File hash for TrainingAnnouncement.jpg
SHA-256daeac66441b88ba22806f6617058a2dbf1ea0ddcc6c94f291542ea853ac6f9d3File hash for TrainingAnnouncement.pdf.lnk
SHA-2564a1a1b1455c3ea91a3d9203ebff025553227302cede6077e821d303655e2c9f2File hash for header.doc
SHA-256aeff39943e254c34187e4a60be3d09d49687439e709eeb4be2b1984310d8ba5cFile hash for body.doc
SHA-256cd147efe37003399e174951927e5fe727a4481756b116f0204a14a64cc62b059File hash for Windowsupdate.exe
SHA-256575305cdaeb1d2187ca6d5ebe32f4c3e3fb53f5ccbe1c0cc257a7f71d84e6f35File hash for TrainingAnnouncement.pdf
SHA-256c4b4647795567ab15528edd1ab1bf37fb50e21b442e59a653051061973e87c02File hash for HolidayNotice.pdf.exe
SHA-2560803521a7e9081f46f8f9f61d72371ecc1f49657f10202fffa9a33f581d8bb39File hash for ACMECS_Pillar_1.vhd
Domainregister[.]mediumser[.]comCommand-and-control domain
IP address38[.]60[.]244[.]141Historical command-and-control address
IP address104[.]64[.]211[.]22Observed command-and-control address
Domainmaui-cocktailbar[.]comRelated command-and-control indicator
Domainappupdate[.]0cmds20cj2cdf8[.]workers.devCloudflare Workers resolver host
Domainregupdate[.]eamakfu49dc28wa[.]workers.devCloudflare Workers resolver host
URLhxxps://appupdate.0cmds20cj2cdf8.workers.dev/A3cmf0q9ASCionCloudflare Workers endpoint used to retrieve backend infrastructure
URLhxxps://regupdate.eamakfu49dc28wa.workers.dev/vere0zme82cadreCloudflare Workers endpoint used to retrieve backend infrastructure

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post China-Nexus Hackers Disguise Malicious VHD as JPEG to Deploy QUICAgent Backdoor appeared first on Cyber Security News.


Discover more from RSS Feeds Cloud

Subscribe to get the latest posts sent to your email.

Discover more from RSS Feeds Cloud

Subscribe now to keep reading and get access to the full archive.

Continue reading