9/22/26, 11:03 AM Myanmar Cyber Threat Landscape, 2016–2026: A Public-Source Review — Malware INFO Blog Sectors in the Selected Public Record Selected public-source record • not national incident prevalence d… ble na -e er b Cy ge na pio es er b Cy re su po ex ta a D k lea ta Da e… er yb rc ula d Mo Government 0 3 2 1 0 Civil society 1 0 0 0 Diplomacy 0 1 0 Finance 1 1 Defence 0 Business registry a… alw dm ete g r Ta … ne an -ch ted s u Tr … ce efa ed sit b e W d… ste ho esit b e W 1 1 1 1 1 1 1 0 0 0 0 0 0 1 1 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 Civil service 0 0 0 1 0 0 0 0 0 0 Cross-border crime 1 0 0 0 0 0 0 0 0 0 Elections 0 0 0 0 0 0 0 0 0 1 ic teg ra St fi… ex Research cutoff: 2026-09-01 • Source and method notes appear in the article Matrix showing selected event categories across government, finance, diplomacy, civil society, health, elections, and business-registry sectors Figure 5. Sector/category intersections in the selected public record. A blank cell means no retained record in this dataset, not that the sector experienced no incidents. Across sectors, several trust relationships recur: Official-channel trust: government sites and downloadable packages can be abused. Identity trust: credentials, session tokens, cookies, personnel data, and identity documents can enable access or harm beyond the first affected system. Application authorization: a valid session is insufficient when record-level access checks are weak. Software-loading trust: DLL side-loading and document-like delivery can make malicious execution appear adjacent to legitimate software or user activity. Public-information trust: defacement and data release can damage confidence even when the event is not covert espionage. Skip to content https://www.malwareinfo.app/blog/posts/myanmar-cyber-threat-landscape-2016-2026/?utm_source=chatgpt.com 13/19

Select target paragraph3