Operation QUICSILVER: China‑Nexus Actor Deploys VHD‑Delivered Go Backdoor Against Myanmar Diplomats
What Happened — A threat‑research team identified a new backdoor, dubbed “Go”, being delivered inside malicious Virtual Hard Disk (VHD) images. The campaign, labeled Operation QUICSILVER, is attributed to a China‑aligned actor and specifically targets diplomatic personnel from Myanmar, using the VHD as a dead‑drop to bypass traditional perimeter defenses.
Why It Matters for Trust & Control Assurance
- The attack illustrates how a compromised third‑party artifact (VHD) can introduce a persistent backdoor, a scenario continuous control‑assurance programs are built to detect and evidence.
- Monitoring vendor‑supplied binaries and maintaining an auditable chain‑of‑trust are essential to prove due‑diligence under NIST CSF 2.0’s “Supply Chain Risk Management” objective.
- Verisq’s Vendor Risk Management capability provides continuous evidence collection on third‑party artifacts, enabling a defensible audit trail when such supply‑chain threats emerge.
Who Is Affected – Government and diplomatic agencies, especially those handling foreign‑state communications; any organization that ingests third‑party VHD images without rigorous verification.
Recommended Actions
- Inventory all VHD and other virtual‑disk assets; verify provenance and hash signatures against trusted sources.
- Integrate automated VHD integrity checks into your CI/CD pipeline and continuous monitoring stack.
- Document the verification process as evidence for supply‑chain risk controls and map it to the relevant control objective in your audit framework.
Technical Notes – The Go backdoor is delivered via a VHD file that, when mounted, executes a hidden PowerShell payload establishing C2 over HTTPS. No public CVE is associated; the technique leverages native Windows mounting behavior. Source: Security Affairs Malware Newsletter Round 112