9/22/26, 11:03 AM Myanmar Cyber Threat Landscape, 2016–2026: A Public-Source Review — Malware INFO Blog KrASIA also reported a claimed 330.5 GB collection associated with roughly 120,000 companies in DICA/MyCO systems. The article described company and officer records and attributed collection claims to an activist group and scraper. This review did not obtain or validate the released material, so the volume, method, and completeness remain sourcereported. The event highlights an important distinction between public availability and safe reuse. Records may contain information that was individually accessible or intended for limited administrative use, yet bulk aggregation changes the risk. Searchability, linkage, persistence, and scale can increase exposure for directors, officers, organizations, and public institutions. 2022: temporary infrastructure exposes a larger collection chain Avast Threat Research, now published by Gen Digital, described a temporary distribution and storage server linked by the researchers to Mustang Panda. Their observation included Myanmar-related government, diplomatic, military, activist, and identity material, with daily gigabyte-scale staging. Reported content included documents, recordings, webmail dumps, passport scans, stored browser credentials, tokens, and cookie sessions. This is one of the strongest technical observations in the selected record, but it still has a boundary. A temporary server is a window into part of an operation. It does not necessarily reveal the complete victim set, every collection method, the duration of access, or the final destination of the data. Skip to content https://www.malwareinfo.app/blog/posts/myanmar-cyber-threat-landscape-2016-2026/?utm_source=chatgpt.com 9/19

Select target paragraph3