expression to investigate if their communications and or devices were compromised by the
authorities If the communications or devices were compromised further analysis was to be utilized
to identify the methods and tools that were used by the authorities or any other groups
Notably no malware infection was detected on any of the devices that were assessed it is possible
that changing political situations can affect and change what specific groups are targeted by the
authorities Despite this several medium and high risk events were found Out of the ten profiles
four received high risks events and 1 received a warning These risks can be categorized as described
below
Common high risk events include:
Personal data being leaked via applications such as Joox Music Candy Crush Jelly B612
Photo Collage Collageable WeChat or QQ
Suspicious connection attempts to IP addresses
Common medium risk events include:
Suspicious connection attempts to IP addresses
Information leaked via insecure HTTP requests
Advertisement trackers were found for all ten profiles with the number of trackers varying from 6 to
157 trackers Emergency VPN recommendations were to minimize the number of applications
showing advertisements on the phone as well as using a privacy blocker browser to reduce the
number of advertisements shown when browsing the web
The complete list of risks can be seen at Annex C
A e
e
f
ici
Faceb
k e
k
Prior to the start of this research study a monitoring organization in Myanmar identified a network of
Facebook pages that was spreading disinformation to manipulate public opinion Because other
networks on Facebook have been used by the military in a similar manner this study sought to
examine whether the network in question was using malware to advance malicious actions by the
authorities
As part of this effort the identified data set was provided to The Citizen Lab which helped to
investigate and analyze the network in April 2020 The Lab s analysis however revealed that the
network s actions were commercially motivated No explicit malicious payloads were detected in the
slice of data that was investigated by the Lab