The Democratic Karen Benevolent Army (DKBA) is an armed group based in Karen State, Myanmar, and aligned with Myanmar’s military regime. In addition to its role as a non-state armed actor controlling territory along the Myanmar–Thailand border, the DKBA has been publicly linked to the protection and operation of large-scale scam-center infrastructure in areas under its control, including the Myawaddy region and the Tai Chang compound. Reporting and sanctions actions have identified the group as facilitating industrialized online fraud operations, particularly pig-butchering, romance-investment, and fraudulent cryptocurrency investment schemes targeting victims abroad, including Americans. The DKBA has been described as enabling criminal networks by allowing illegal compounds to operate under its protection, securing scam facilities, and partnering with or serving the interests of Chinese organized crime-linked operators. Scam compounds associated with the group have been tied to forced labor and human trafficking, with victims coerced into conducting online fraud under threat of violence. Abuse attributed to personnel operating in DKBA-controlled areas has included beatings, torture, and other cruel treatment of trafficked workers. Known leaders named in connection with these activities include Saw Steel, Saw Sein Win, and Saw San Aung. Additional DKBA-linked figures identified in sanctions and reporting include Saw Kyaw Hla and Saw Eh Le Htoo. Associated commercial facilitators and linked entities have included Trans Asia International Holding Group Thailand Company Limited and Troth Star Company. The group has also been connected to other scam-center development and protection networks in Karen State. Operationally, DKBA-linked scam ecosystems have relied on social engineering, spoofed investment platforms, fraudulent cryptocurrency services, and online outreach through messaging and social media platforms. The actor’s role is best characterized as territorial protection, facilitation, and participation in transnational cyber-enabled fraud rather than conventional state-directed cyber espionage. Its activities support organized crime revenue generation and have also been described as contributing funds to armed-group and illicit trafficking networks in Myanmar.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Facilitates large-scale scam centers in territory it controls in Myanmar by protecting illegal compounds and enabling criminal networks to operate there; reports also cite its soldiers participating in violence against victims trapped inside compounds.
Previously designated as part of the scam center ecosystem in the region, representing the armed-group layer of the infrastructure supporting scam operations.
Runs scam centers including Tai Chang in Myanmar that conduct pig butchering and investment fraud schemes.
Identified by US officials as controlling the Tai Chang scam compound in Myanmar, which is implicated in large-scale cryptocurrency/investment fraud operations targeting US victims and allegedly leveraging Starlink satellite internet terminals for connectivity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.