9/22/26, 11:03 AM
Myanmar Cyber Threat Landscape, 2016–2026: A Public-Source Review — Malware INFO Blog
The practical lesson is to preserve campaign context without importing unsupported detail.
Vendor attribution can be useful for comparing tooling and infrastructure, yet local defenders
still need endpoint, identity, network, and server evidence from the affected environment
before deciding what happened there.
2020–2022: access control, trusted delivery, and
strategic collection
2020: COVID-19 QR-pass exposure
KrASIA reported in October 2020 that changing digits in a URL could allow users to view or
alter other records in a Yangon COVID-19 QR-pass system. The reported weakness concerns
object-level access control: an application must verify that the current user is authorized for
the specific record requested, not merely that a record identifier exists.
This research did not reproduce the weakness or access affected records. The case is
retained because it illustrates that cyber risk is not limited to malware. A simple authorization
failure in a high-demand public service can expose identity and travel-related data while
undermining confidence in an emergency system.
2021: a trusted download channel reportedly delivers a loader
The Record reported in June 2021, citing ESET analysis, that a Myanmar Unicode font archive
offered through the president's office website had been modified to include an Acrobat.dll
Cobalt Strike loader. The public report supports the trusted-channel-abuse observation; it
does not let this paper independently reconstruct the server compromise, determine how
many users executed the archive, or strengthen the source's qualified attribution.
For defenders, official distribution paths need the same release controls expected from
software repositories: controlled build provenance, hashes, signing where appropriate, change
monitoring, least-privileged publishing, and rapid revocation. For investigators, a familiar
filename or official referrer is context—not proof that the payload is benign.
Skip to content
2021: company-registration data reportedly released
https://www.malwareinfo.app/blog/posts/myanmar-cyber-threat-landscape-2016-2026/?utm_source=chatgpt.com
8/19