9/22/26, 11:03 AM Myanmar Cyber Threat Landscape, 2016–2026: A Public-Source Review — Malware INFO Blog 1. What was directly observed? Examples include a file, server, delivery chain, altered web page, or application behavior. 2. Who observed it? An affected organization, technical research team, public agency, journalist, or third party may have different access. 3. What remains inferred? Campaign ownership, intent, victim scope, and final data destination are often assessments rather than direct observations. 4. What is unavailable? Private telemetry, incident timelines, forensic images, disclosure constraints, and unreported events can materially change the picture. Defensive implications for Myanmar organizations The decade does not support one universal detection rule. It supports a layered operating model. Protect trusted publishing paths. Inventory who can change public websites, software packages, fonts, documents, and download archives. Monitor changes, preserve version history, and publish verifiable hashes or signatures where practical. Treat an unexpected server-side file change as an incident requiring scope analysis. Harden identity beyond passwords. Use phishing-resistant multifactor authentication where feasible, restrict legacy authentication, monitor abnormal sessions, and make token/session revocation part of playbooks. Browser credential stores and active sessions are evidence targets, not merely user conveniences. Test authorization at the object level. Public-service portals should verify entitlement for every requested record and action. Rate limits and unpredictable identifiers can help, but neither replaces authorization. Testing must avoid accessing real users' records without authority. Monitor legitimate execution relationships. DLL side-loading and trusted-binary abuse require visibility into which process loaded which module, from which path, with what signer and hash, and what happened next. A tool name or export name alone does not establish Skip to content malicious behavior; correlate file, process, memory, registry, and network evidence. https://www.malwareinfo.app/blog/posts/myanmar-cyber-threat-landscape-2016-2026/?utm_source=chatgpt.com 15/19

Select target paragraph3