9/22/26, 11:03 AM
Myanmar Cyber Threat Landscape, 2016–2026: A Public-Source Review — Malware INFO Blog
records, and financial portals. It also shows that cyber harm extends beyond malware to
application design, bulk data exposure, account abuse, public disruption, and organized online
fraud.
The strongest analytical habit is separation. Separate observation from attribution. Separate
an exposed server from a complete operation. Separate subscriptions from people and
connectivity from incident volume. Separate a reported leak from independently examined
evidence. When those boundaries remain visible, public-source research becomes more
useful to defenders—and less likely to manufacture certainty that the evidence cannot
support.
References
Citizen Lab, Between Hong Kong and Burma: Tracking UP007 and SLServer Espionage
Campaigns, April 18, 2016.
Democratic Voice of Burma, Hackers target govt websites in cyber spillover from Arakan
crisis, September 5, 2017.
Kaspersky Securelist, APT review: what the world's threat actors got up to in 2019,
December 4, 2019.
KrASIA, Cyberattacks hobble Myanmar's COVID-19 QR pass system, expose massive
security flaws, October 1, 2020.
KrASIA, Massive data trove from 120,000 Myanmar companies surface online in Wikileaksstyle release, February 22, 2021.
The Record, Backdoor malware found on the Myanmar president's website, again, June 3,
2021.
Gen Digital / Avast Threat Research Team, Hitching a ride with Mustang Panda, December
2, 2022.
UNODC, Casinos, cyber fraud, and trafficking in persons for forced criminality in Southeast
Asia, September 2023.
SkipCERT-EU,
to contentCyber Security Brief 24-03 — February 2024, February 2024.
https://www.malwareinfo.app/blog/posts/myanmar-cyber-threat-landscape-2016-2026/?utm_source=chatgpt.com
17/19