9/22/26, 11:03 AM Myanmar Cyber Threat Landscape, 2016–2026: A Public-Source Review — Malware INFO Blog Plan for evidence preservation. Decide in advance which logs, memory captures, endpoint packages, cloud audit records, and network records can be collected lawfully. Evidence can contain credentials, personal data, and sensitive organizational content; access, retention, transfer, and disclosure require controls. Report and coordinate. MM-CERT publishes alerts, advisories, activities, and an incidentreporting route. Organizations should align escalation with legal obligations, sector rules, contracts, and the sensitivity of affected data. A public alert can improve readiness, but public disclosure should not precede containment or expose victims unnecessarily. Limitations This paper is constrained by public availability, publisher access, language, archive stability, and disclosure practices. The absence of a public report is not evidence that an incident did not occur. Publication dates may differ from incident dates, and a year with more retained records may simply have better reporting. The event categories are editorial groupings, not a universal taxonomy. Sector labels can overlap. Campaign and actor names are reproduced only at the confidence level used by their sources. No attempt was made to identify private victims, reproduce vulnerabilities against live systems, obtain leaked records, execute malware, or contact suspected infrastructure. The PTD chart ends in 2020 and measures subscriptions rather than unique people. The UNODC report uses a qualitative regional methodology. Several breach and leak entries rely on secondary reporting rather than primary forensic material. These limitations make the review suitable for defensible orientation and research planning—not for calculating a national incident rate, assigning liability, or declaring attacker intent. Conclusion From 2016 through the September 2026 cutoff, Myanmar-linked public reporting shows repeated pressure on institutional trust: trusted websites and archives, government and diplomatic endpoints, browser identities, public-service applications, business and personnel Skip to content https://www.malwareinfo.app/blog/posts/myanmar-cyber-threat-landscape-2016-2026/?utm_source=chatgpt.com 16/19

Select target paragraph3