People’s Defense Force Zoland, also referred to as PDF Zoland, is a Myanmar anti-junta resistance formation operating in the context of the post-2021 civil war. It is associated with the broader armed resistance ecosystem active in western Myanmar, particularly in areas linked to Zomi communities near the India-Myanmar frontier. Public reporting has identified the group as part of the resistance movement opposing Myanmar’s military authorities. It has been publicly associated with the presence of foreign volunteers, including individuals from the United States and the United Kingdom, who were depicted as having joined the resistance. High-confidence reporting provided here does not establish specific cyber operations, malware use, intrusion activity, ransomware involvement, or other digital tradecraft attributable to the group. Available information also does not support a confident assessment of a state sponsor, formal sub-groups, or a defined cyber threat profile.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.