9/22/26, 11:03 AM
Myanmar Cyber Threat Landscape, 2016–2026: A Public-Source Review — Malware INFO Blog
KrASIA also reported a claimed 330.5 GB collection associated with roughly 120,000
companies in DICA/MyCO systems. The article described company and officer records and
attributed collection claims to an activist group and scraper. This review did not obtain or
validate the released material, so the volume, method, and completeness remain sourcereported.
The event highlights an important distinction between public availability and safe reuse.
Records may contain information that was individually accessible or intended for limited
administrative use, yet bulk aggregation changes the risk. Searchability, linkage, persistence,
and scale can increase exposure for directors, officers, organizations, and public institutions.
2022: temporary infrastructure exposes a larger collection chain
Avast Threat Research, now published by Gen Digital, described a temporary distribution and
storage server linked by the researchers to Mustang Panda. Their observation included
Myanmar-related government, diplomatic, military, activist, and identity material, with daily
gigabyte-scale staging. Reported content included documents, recordings, webmail dumps,
passport scans, stored browser credentials, tokens, and cookie sessions.
This is one of the strongest technical observations in the selected record, but it still has a
boundary. A temporary server is a window into part of an operation. It does not necessarily
reveal the complete victim set, every collection method, the duration of access, or the final
destination of the data.
Skip to content
https://www.malwareinfo.app/blog/posts/myanmar-cyber-threat-landscape-2016-2026/?utm_source=chatgpt.com
9/19