Phishing
4
4.5
Simple “phishing”, where fraudulent emails are sent with the intention of extracting money
or obtaining personal information such as bank details, have been seen in Myanmar for
over a decade. Myanmar recipients have been taken in by fake ‘You have won the
lottery!’ emails, and letters from the President of the World Bank.
DDoS Attacks
Myanmar suffered a huge DDoS attack in 2010, just before the election. The main Internet
service provider, MPT, was overwhelmed and the attack essentially took the country
offline. The attack was discovered by the research organisation Arbour Networks, which
reported the attack was larger than the 2007 attack on Estonia, but could not establish its
origin. Speculation ranged from placing blame on the Government of Myanmar in order to
disrupt the election, to external hackers with unknown motives. 420
In 2011, Irrawaddy reported they had been victim to likely DDoS attacks, forcing the
website to be temporarily shut down. Hackers also penetrated Irrawaddy’s central server
and planted false new stories on the website’s front page, claiming a popular Burmese
actress had died. It was also suspected hackers had gained access to confidential
information stored on the server, such as the identity of sources. The Irrawaddy hired
European security specialists to investigate the attacks, who traced to an IP address in
London. 421
A variety of hacker groups have been reported as active in Myanmar. These groups
include the Kachin Cyber Army, Bangladeshi Cyber Army and Indonesian Cyber Army. 422
Blink Hacker Group has also been reported to be active. 423 Attacks have typically included
website defacement or service takedown via a denial of service attack (DDoS). 424
Targeting Burmese Exiles with Malware
Throughout the 2000’s, there were repeated reports that Burmese exiles were being
targeted by the state with malicious software, or “malware”, by concealing computer
viruses in emails, sent to targets with titles such as ‘Happy Birthday’ or ‘I need help’. The
purpose of these attacks at this stage appears to have been to disrupt computers,
rendering them unusable, or crashing exile media websites, rather than for the purpose of
monitoring user activity. 425 However more recently, the purpose of malware attacks seem
to have been to gain access to confidential information (See above and Chapter 4.4 on
Surveillance).
Existing Cyber Security Management and Policy in Myanmar
As the ICT sector grows in Myanmar, and more services are introduced online, such as ebanking, maintaining the availability of services, integrity of systems and protection of
420
See Infosecurity, “Massive DDoS Attack Knocks Burma Offline” (5 November 2010).
Shawn W. Crispin, “Burmese Exile News Site Endures Hacking, DDoS Attacks” Committee to Protect
Journalists (CPJ) (2 May 2011).
422 Bill O’Toole, “Email Hacking Exposes Cybercrime in Myanmar“ The Myanmar Times (20 February 2013).
423 Softpedia, “1,000 Myanmar Websites Hacked by Blink Hacker Group” (3 January 2013) and Blink Hackers
Group.
424 A denial of service attack involves flooding a network with information, which overwhelms a website or
services server used for hosting. This can involve a single attacker, or a group of compromised computers
(bot-net) that flood the network (called a distributed denial of service attack).
425 Rehmonnya.org “‘I Need Help’ Email Virus Attacks Burmese Exile Groups“ (4 October 2008).
421
184
PAGE
CHAPTER 4.5: CYBER-SECURITY