9/22/26, 11:03 AM Myanmar Cyber Threat Landscape, 2016–2026: A Public-Source Review — Malware INFO Blog The practical lesson is to preserve campaign context without importing unsupported detail. Vendor attribution can be useful for comparing tooling and infrastructure, yet local defenders still need endpoint, identity, network, and server evidence from the affected environment before deciding what happened there. 2020–2022: access control, trusted delivery, and strategic collection 2020: COVID-19 QR-pass exposure KrASIA reported in October 2020 that changing digits in a URL could allow users to view or alter other records in a Yangon COVID-19 QR-pass system. The reported weakness concerns object-level access control: an application must verify that the current user is authorized for the specific record requested, not merely that a record identifier exists. This research did not reproduce the weakness or access affected records. The case is retained because it illustrates that cyber risk is not limited to malware. A simple authorization failure in a high-demand public service can expose identity and travel-related data while undermining confidence in an emergency system. 2021: a trusted download channel reportedly delivers a loader The Record reported in June 2021, citing ESET analysis, that a Myanmar Unicode font archive offered through the president's office website had been modified to include an Acrobat.dll Cobalt Strike loader. The public report supports the trusted-channel-abuse observation; it does not let this paper independently reconstruct the server compromise, determine how many users executed the archive, or strengthen the source's qualified attribution. For defenders, official distribution paths need the same release controls expected from software repositories: controlled build provenance, hashes, signing where appropriate, change monitoring, least-privileged publishing, and rapid revocation. For investigators, a familiar filename or official referrer is context—not proof that the payload is benign. Skip to content 2021: company-registration data reportedly released https://www.malwareinfo.app/blog/posts/myanmar-cyber-threat-landscape-2016-2026/?utm_source=chatgpt.com 8/19

Select target paragraph3