Threats Affecting Myanmar
View all threats affecting or targeting Myanmar. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Myanmar
Click on any threat for detailed analysis and mitigation recommendations
The China-nexus threat cluster UAT-11587 has been conducting targeted attacks against government and policy organizations in eight Asian countries since September 2025. It uses spear-phishing campaigns with political and diplomatic lures to deliver a Rust-compiled backdoor named Antino. Antino uniquely uses Microsoft 365 services such as Outlook and OneDrive for command-and-control communication instead of traditional C2 servers. The backdoor enables reconnaissance, command execution, file transfer, shellcode loading, and persistence. The campaign leverages Cloudflare infrastructure for delivery and employs DLL sideloading techniques. Join the discussion | AlienVault OTX General | 09/30/2026, 15:17:20 UTC Added: 09/30/2026, 18:48:38 UTC |
Cisco Talos identified a China-nexus cyber espionage campaign named UAT-11587 targeting government and policy organizations across Asia, including Taiwan, India, the Philippines, and Cambodia. The campaign uses spear-phishing emails with tailored decoy documents to deliver a Rust-compiled Windows backdoor called Antino. Antino supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading, and persistence. Its command-and-control communication uniquely operates through Microsoft 365 applications using Microsoft Graph to interact with Outlook and OneDrive. The campaign has affected at least 16 institutional environments across eight Asian countries with approximately 350 compromised endpoints. Talos assesses this activity as an intelligence gathering operation with moderate to high confidence. No patch or remediation guidance is provided in the report. Join the discussion | Cisco Talos | 09/30/2026, 10:00:01 UTC Added: 09/30/2026, 10:09:13 UTC |
A China-nexus threat actor is targeting Myanmar government personnel and diplomats through Operation QUICSILVER, delivering malware via Virtual Hard Disk files disguised as JPEG images. The campaign uses Burmese-language lures impersonating Myanmar's Information Technology and Cyber Security Department, including graduation ceremony invitations. The multi-stage infection chain begins with a malicious LNK file that abuses ftp.exe to execute scripts, reconstructs payloads from split files, and deploys QUICAgent, a custom Go-based backdoor. The implant retrieves C2 infrastructure through Cloudflare Workers, communicates over HTTP/3 using QUIC protocol, and employs RC4 encryption. Deleted documents recovered from the VHD reveal interest in ASEAN affairs, BIMSTEC, and Myanmar diplomatic activities. Three related campaigns were identified between April and July 2026, sharing similar TTPs and infrastructure. Join the discussion | AlienVault OTX General | 08/17/2026, 15:03:53 UTC Added: 08/18/2026, 09:26:43 UTC |
HoneyMyte APT group (also known as Mustang Panda) has significantly upgraded its CoolClient backdoor with kernel-level rootkit capabilities. The latest variant deploys a signed kernel-mode driver (msagent.sys) as a Windows service, enabling advanced stealth features including process hiding, file and registry protection, and network traffic filtering. The multi-stage malware uses DLL sideloading through a legitimate Sangfor application, establishes persistence via scheduled tasks and AutoRun entries, and implements UAC bypass techniques. CoolClient now injects into synchost.exe and communicates with the kernel driver through IOCTL requests. The driver hooks Nsiproxy to filter C2 addresses from network information. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia, with PlugX serving as the initial infection vector before CoolClient deployment. Join the discussion | AlienVault OTX General | 08/14/2026, 10:50:02 UTC Added: 08/14/2026, 11:26:13 UTC |
0 An investigation using Silent Push's Traffic Origin and residential proxy data revealed a suspicious Chinese VPN provider. The analysis focused on IP address 205.198.91.155, which showed unusual traffic from Russia, China, Myanmar, Iran, and Venezuela. This IP was linked to the domain lvcha.in, hosting a Chinese-language VPN. Further investigation uncovered nearly 50 related domains promoting the same VPN, suggesting attempts to bypass country-level firewalls. The VPN's infrastructure was found to use residential proxies and had connections to various high-risk countries. This case study demonstrates the importance of verifying physical and technical behaviors of connections to protect against fraud and state-sponsored actors using stolen identities and spoofed locations. Join the discussion | AlienVault OTX General | 02/10/2026, 09:09:44 UTC Added: 02/10/2026, 10:15:26 UTC |
0 A Stored Cross Site Scripting (XSS) vulnerability was found in "/history.php" in Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary code via the Name, Phone, and Email parameter fields. Join the discussion | CVE Database V5 | 08/22/2024, 00:00:00 UTC Added: 02/25/2026, 21:42:35 UTC |
Showing 1 to 6 of 6 results