9/22/26, 11:03 AM
Myanmar Cyber Threat Landscape, 2016–2026: A Public-Source Review — Malware INFO Blog
This category must remain separate from state-linked espionage reporting. The actors,
economics, operational models, and victim harms differ. At the same time, enterprise defenses
still intersect with the ecosystem: impersonation, deceptive recruitment, social engineering,
account takeover, payment abuse, and identity misuse can reach employees and customers
across borders.
2024: suspected government targeting remains qualified
CERT-EU's February 2024 brief summarized reporting that Myanmar's ministries of Defence
and Foreign Affairs were suspected targets between November 2023 and January 2024. The
brief used qualified language: Mustang Panda was suspected and backdoor deployment was
described as likely. This paper preserves those qualifiers because the source is a CERT
summary rather than direct incident evidence from the ministries.
Analysts should resist turning repeated campaign names into certainty. Attribution can carry
several levels: shared malware, shared infrastructure, behavioral resemblance, a vendor
assessment, government assessment, or direct operational evidence. Public reporting often
exposes only part of that ladder.
2025: a modular toolset, but a narrow starting sample
In a two-part April 2025 investigation, Zscaler ThreatLabz documented ToneShell and
StarProxy and PAKLOG, CorKLOG, and SplatCloak. The investigation began with two machines
at an organization in Myanmar and described DLL side-loading, remote-access and proxy
capabilities, keylogging, and attempts to impair security telemetry.
The detail is valuable for detection engineering, but two starting machines do not establish
prevalence across a country. Nor does a campaign tool catalog prove that every component
executed on every target. Defenders should convert the report into testable hypotheses—
specific file relationships, loading behavior, persistence, network destinations, and telemetry
gaps—then confirm or reject them using local evidence.
Also in 2025, Burma News International reported exposure of civil-service personnel
information including names, positions, departments, and home addresses, followed by tighter
Skip to content
https://www.malwareinfo.app/blog/posts/myanmar-cyber-threat-landscape-2016-2026/?utm_source=chatgpt.com
11/19