expression to investigate if their communications and or devices were compromised by the authorities If the communications or devices were compromised further analysis was to be utilized to identify the methods and tools that were used by the authorities or any other groups Notably no malware infection was detected on any of the devices that were assessed it is possible that changing political situations can affect and change what specific groups are targeted by the authorities Despite this several medium and high risk events were found Out of the ten profiles four received high risks events and 1 received a warning These risks can be categorized as described below Common high risk events include: Personal data being leaked via applications such as Joox Music Candy Crush Jelly B612 Photo Collage Collageable WeChat or QQ Suspicious connection attempts to IP addresses Common medium risk events include: Suspicious connection attempts to IP addresses Information leaked via insecure HTTP requests Advertisement trackers were found for all ten profiles with the number of trackers varying from 6 to 157 trackers Emergency VPN recommendations were to minimize the number of applications showing advertisements on the phone as well as using a privacy blocker browser to reduce the number of advertisements shown when browsing the web The complete list of risks can be seen at Annex C A e e f ici Faceb k e k Prior to the start of this research study a monitoring organization in Myanmar identified a network of Facebook pages that was spreading disinformation to manipulate public opinion Because other networks on Facebook have been used by the military in a similar manner this study sought to examine whether the network in question was using malware to advance malicious actions by the authorities As part of this effort the identified data set was provided to The Citizen Lab which helped to investigate and analyze the network in April 2020 The Lab s analysis however revealed that the network s actions were commercially motivated No explicit malicious payloads were detected in the slice of data that was investigated by the Lab

Select target paragraph3