DYSPHOR1A is a financially motivated cybercrime actor associated with database breaches, credential theft, and the sale of stolen information and compromised account access. Its targeting is concentrated in Myanmar, with additional activity against organizations in Thailand, Indonesia, and India. Targeted sectors include government and law enforcement, financial services, education, telecommunications, vehicle leasing and transportation, and professional services. Activity attributed to DYSPHOR1A in August and September 2026 involved the exposure of customer and employee information, student accounts and academic records, financial and operational data, and law-enforcement personnel records. Stolen datasets included passwords and administrative credentials. The actor offered payment-platform agent and user information for sale and advertised administrative access to a vehicle-leasing company's platform. DYSPHOR1A is also categorized as a ransomware group, but its established activity centers on data compromise and monetization; specific encryption, ransom-demand, and extortion mechanisms are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed ransomware attack against Myanmar's Road Transport Administration Department (RTAD), with an alleged 1.08 GB full-database dump from the government transport-services portal.
DYSPHOR1A claims to have compromised the Road Transport Administration Department (RTAD) in Myanmar and stolen a 1.08 GB full database dump. The post provides no ransom demand, deadline, attack-vector details, or sample data.
Alleged ransomware and data-extortion operation targeting CitizensPay/CTZPay, a Myanmar mobile digital-wallet and payment platform. The reported stolen data comprises approximately 30 GB of agent-user information, with an advertised price range of $7,000 to $25,000.
DYSPHOR1A claims to have compromised CitizensPay (CTZPay), a Myanmar mobile-wallet and payment platform. The post alleges 30 GB of compromised agent-user information and lists a price range of $7,000 to $25,000, without a publication deadline or supporting sample.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.