Myanmar
TSG export customer. Justice for Myanmar's 2025 'Silk Road of Surveillance' report.
also: MM, Burma
The cyber-narrator/cn-ui repo (the CyberNarrator/网络叙事者 frontend, 3123 commits across 21.08-24.11 tags) maintains dedicated deployment branches "dev-24.01-m22" (M22 = Myanmar per taxonomy) and "dev-xj-0111" (Xinjiang), confirming CyberNarrator is actively built and shipped per-deployment for both an export customer (Myanmar) and a domestic site (Xinjiang) as of 2024, and ships EN/RU/ZH localization plus per-country geojson map data (including kazakhstanLow.json, ethiopiaLow.json, myanmarLow.json) consistent with a multi-country tracking dashboard.
The TSG session_record schema in use at the Myanmar (YGN-MYTEL) deployment includes, in the same per-session record, both TLS-interception status fields (proxy_pinning_status, proxy_intercept_status, proxy_cert_verify, proxy_passthrough_reason, proxy_intercept_error) and individual-subscriber-identity fields (subscriber_id, imei, imsi, apn, phone_number) -- confirming MITM/certificate-interception capability and per-person subscriber correlation are built into the same live logging pipeline at an actual export site, not just described separately in marketing/config material.
Raw TSG session_record export logs dated Nov 2024, tagged device_group 'YGN-MYTEL' (Yangon, Mytel), directly corroborate the leak's M22=Myanmar/Mytel/Yangon site-codename mapping with live production data: individual SSL sessions are classified by app as 'Hotspot Shield VPN' (destination get.adobe.com, likely a fronting/CDN endpoint) and allowed under a named whitelist rule 'whitelist_102024', geolocated client-side as Myanmar.Yangon.Yangon.
Under the internal "M22" project (deployment site "YGN-MYTEL" confirms this is Myanmar, at the Mytel carrier), Geedge runs a continuous, individually-tracked signature-extraction pipeline against named commercial VPN apps (Super Unlimited VPN, NotVPN, Avira Phantom, Bitdefender VPN, Thunder VPN, Panda VPN, Mouse VPN, HaloVPN, GoFly VPN, Kiwi/Kuto/Greennet/Gulf Super/Hatunnel+ VPN, and a customer-provided list of 141 more): active probing of app refresh/connect behavior (including automated UI-driving scripts) extracts server IP/FQDN lists, separately for free vs. paid tiers and Android vs. iOS, which are then loaded as blocklist objects and validated against a false-positive ("CT"/穿透) test pass in a separate demo environment before deployment.
An 'Equipment label and cable label design' spec's data-center appendix lists far more Myanmar carrier taps than previously documented: Yangon sites for NDC, Mytel, MPT, ATOM, Ooredoo, Frontiir, Campana, GTG, GTMH, StreamNet, China Unicom, MTN and MBT; Mandalay sites for Mytel/MPT/ATOM/Ooredoo/GTG/China Unicom; plus Tachilek, Ketong, Myawaddy and Muse border sites; and a Naypyidaw entry 'NPT-NCCC' alongside 'NPT-MPT', plausibly a tap tied to Myanmar's National Cyber [Security] Coordination Center in the capital. The equipment-type table also confirms 'TSG-X' as the formal hardware model code.
A physical rack-elevation diagram for 'YGN Data Center Container 2' (Yangon, Myanmar -- taxonomy site codename M22) shows multiple 1U servers in racks 7-12 explicitly labeled 'TSG OLAP and Cyber Narrator' interleaved with plain 'TSG OLAP' nodes, each with its own IPMI management IP, directly corroborating that the CyberNarrator component is deployed as live production infrastructure at the Myanmar M22 site rather than only described in internal documentation.
The NEZHA monitoring-platform build repo (nezha/nz-build) contains commits building Myanmar-specific map tiles ("build: M22 7-11 pbf", "build: make myanmar 8-9"), directly corroborating the M22=Myanmar site-codename mapping already established in the corpus via an independent internal build artifact, and separately packages a Russian-language HASP license driver ("hasp_rus") into the NZ installer.
A security policy literally named "Lantern_vpn_test" was configured and actively enforced at the M22 (Myanmar) TSG deployment as of June 27 2024 — Lantern had a live, named blocking policy in production, not just a backlog research item.
A Myanmar deployment (M22 project) ticket requested Geedge R&D extract detection fingerprints for Signal (specifically targeting its anti-censorship "circumvention" toggle, currently evading blocking), LetsVPN, and LanternVPN — LanternVPN explicitly flagged lower priority with no fixed deadline given expected difficulty.
Confirms TSG deployment extends beyond Yangon/Mandalay to Myanmar border towns Tachileik, Kengtung, Myawaddy, and Muse, backhauled to the Yangon DC via VPN devices required to meet <100ms latency and >=1Gbps bandwidth.
TSG's app/protocol detection ("AppSketch" / context_based_detector plugin, part of the SAPP packet pipeline) is not purely static-signature: each detection rule can be an arbitrary Lua script (APP_SIG_LUA_SCRIPTS table) executed per-session in a per-worker-thread LuaJIT VM, with access to packet payload, session context counters, and helper functions (APP.data, APP.context.c2s_count, APP.log_debug, APP.append_extra_info). A validation CLI tool (luac-tool) checks script syntax, timeout, and return-value type before import.
TSG is deployed across multiple named Myanmar telecom carriers (Mytel and MPT/Myanmar Posts and Telecommunications) at both Mandalay (MDY) and Yangon (YGN) sites -- device naming convention TSG-OS-<city>-<carrier>-TSGX<n> -- confirming a nationwide, multi-operator rollout rather than a single-ISP pilot.
Internal asset naming ("YGN-MYTEL-EF01-SMBIO01") ties a TSG deployment directly to Mytel, the Myanmar telecom carrier, at a Yangon (YGN) site -- corroborating and adding carrier-level specificity to the Myanmar export relationship already documented by Justice for Myanmar's "Silk Road of Surveillance" report.
For the M22 project (domestic-China-labeled training ticket, but M22 is elsewhere confirmed as a Myanmar deployment), Geedge explicitly instructs trainers to describe 'Cyber Narrator' only as a black-box ML capability, to avoid revealing the internal domain tsg.bj.internal.geedge.net, and to omit the company logo from training materials — i.e. deliberate concealment of Geedge's involvement and internal infrastructure from the training audience.
Project "M22" (running the Turbo VPN/7VPN extraction program) is tied to a site logged as "YGN NDC" -- YGN = Yangon, Myanmar; NDC reads as National Data Center. Corroborates M22 as Myanmar via primary-source project/site code.
Confirms TSG-OS deployment directly on Mytel's (Myanmar carrier) network with named host identifiers at Yangon (YGN-MYTEL-TSGX025, YGN-MYTEL-TSGX026) and Mandalay (MDY-MYTEL-TSGX001), corroborating and specifying the M22/Myanmar deployment beyond what Justice For Myanmar's public report identified.
Internal project codename "M22" corresponds to a Myanmar deployment at telecom operator Mytel (site id "YGN-MYTEL", Yangon), running on TSGX hardware appliances (at least 25 units observed at this one site) alongside the TSG-OS software stack — extending prior public reporting (Justice for Myanmar) with the specific internal site/customer codename and confirmed hardware scale.
Multi-week TSG engineering investigation of iTOP VPN (requested by an Ethiopia deployment, cross-tested in a Myanmar environment) found blocking only takes effect for VPN sessions established AFTER a detection policy is pushed; a VPN already connected before the policy loads is never blocked or logged, regardless of signature type (SNI or server-IP).
Two hands-on QA 拨测 (dial-test) reports document engineers connecting to Ooredoo Myanmar's mobile hotspot and to a 'Campana' WiFi network supplied by 'NCSC', then repeatedly browsing target sites (pixiv.net, zerohedge.com, internxt.com, littledayout.com, palaceskateboards.com, among others) while packet-capturing and cross-checking TSG 'statistics' policy hits against specific internal tap addresses (YGN-Ooredoo: 10.164.12.x, YGN-CPN: 10.169.12.x) -- direct field verification of inline/mirror tap function at named Myanmar carrier sites.
Geedge ran an ongoing, systematically-numbered program extracting detection fingerprints for individual VPN and non-VPN apps for the Myanmar (M22) deployment, tracked with weekly-cadence per-app tickets; methodology combined packet capture, DNS/domain analysis, and fixed-port protocol identification, validated in a live test environment before shipping, with results tracked as "CT" (successfully blocked) or not.
M22's extraction against "VPN Hero" (OpenVPN-based) recovered 13 FQDN + 13 IP indicators; FQDNs follow a "zampakuto...shop" template. Post-signature testing in the Myanmar demo environment found no successful connections on Android/iOS.
Documents the exact methodology used to derive a block signature for 'Giti VPN': TLS interception (fiddler) to decrypt the app's traffic, identifying its control/initialization domain and a second per-session domain pattern, then blocking by those two domain-name features rather than deep packet content.
Project "M22" runs a standing weekly program to extract and patch detection signatures against "Turbo VPN": automated dial-testing continuously discovers server IPs (tens to hundreds/week), each batch packaged into a dated JSON patch file, validated for both blocking efficacy and false-positive risk before rollout. Ran continuously Aug-Nov 2024 in the source ticket.
The same M22 weekly-extraction program runs in parallel against "7VPN": automated dial-tests repeatedly found its free-tier nodes already non-functional/blocked across weekly checks Aug-Oct 2024, indicating sustained monitoring even absent a signature update.
M22's VPN signature-extraction workflow, when API sniffing (fiddler) fails, escalates to decompiling the target APK: jadx-gui, then apktool -- which recovered node information for "Luna VPN" after the first two methods failed.
Myanmar deployment (M22) systematically reverse-engineered and blocked Orbot (Tor's official Android client) and ProtonMail, alongside numerous consumer VPN apps, via the AppSketch feature-extraction pipeline. Orbot: 287 server IPs extracted across multi-hop nodes, one connection mode fully blocked. ProtonMail: mail server IPs/FQDNs extracted, blocking verified as full service denial (cannot send, receive, download attachments, or create a new account) on Android and iOS.
M22 runs a large-scale automated pipeline against numerous commercial VPN apps: APK decompilation + HTTPS-proxy interception to extract servers/FQDNs, automated dial-testing at volume (one app: 17,554 dial-tests, 4,073 servers discovered, 94% 24-hour block rate), and OpenCV-based automated ad-dismissal to keep test automation running unattended.
Internal project codenames decode to specific customers: M22 = Myanmar (operators Mytel, Ooredoo Myanmar, and ATOM; sites YGN=Yangon, MDY=Mandalay), K18 = Kazakhstan (site renamed Nur-Sultan to Astana in OLAP config), E21 = Ethiopia (operator Safaricom Ethiopia; sites ADAMA-PE/SSM-PE to KLT-IGW/SHQ-IGW), WMS-UTR = Pakistan.
TSG-X's NEZHA monitoring-dashboard repo (tango/tsgx_hardware) shows certstore-specific dashboard charts being added ("Add certstore charts") and, three weeks later, the dashboard-template set updated explicitly sourced from the M22 (Myanmar) deployment ("sync chart from m22"), confirming certstore (TLS-interception) has its own operational monitoring and that NEZHA dashboard templates are shared from the Myanmar site into the general TSG-X product line.
Geedge's VPN-app signature-extraction methodology (M22/Myanmar project, run weekly per-app) is primarily IP-address-list-based rather than protocol-fingerprint-based: automated scripts enumerate each VPN app's server IPs (extraction runs cited pulling 7-200+ IPs per test cycle for apps like BigMama VPN, Giti VPN, JumpJumpVPN), which are then pushed as blocking signatures and validated against a live test environment plus a separate false-positive ('误封') test environment before deployment.
The same M22-tagged VPN-finder plugin set implements active UDP probing to elicit and harvest server IP addresses from CyberGhost VPN's protocol behavior, and separately fingerprints Windscribe VPN via TLS certificate features — two distinct active-probing/fingerprinting techniques feeding the same central VPN-blocklist knowledge base, with an explicit configurable active-scan packet rate.
The "intelligence-learning-engine/vpn-finder-plugins" repo was initialized specifically for the M22 (Myanmar) deployment ("Init: M22初始化", branches "24.08_M22"/"tsg24.02_M22") and implements per-service detection plugins for at least nine commercial VPN products (CyberGhost, ProtonVPN, TurboVPN, Windscribe, IPVanish, Ivacy, VPN Unlimited, GeckoVPN, Hotspot Shield) plus Psiphon3, feeding discovered server identifiers into a central "knowledge base" that field deployments sync from on their own release cadence.
A dial-testing ('拨测') log documents systematic active-probing/reachability testing from a 'YGN-GTG' (Yangon Gateway, Myanmar) network node against six overseas test sites in Singapore, France, the US, New Zealand, South Africa, and Chile, using packet capture plus flow statistics to quantify one-way vs two-way flow completion (0-45%% flow loss observed per site) through gateway node IPs 'YGN-GTG: 10.173.12.x' -- direct empirical evidence of connectivity/blocking-effectiveness QA testing tied to the Myanmar (M22) Yangon deployment, run against an 'NCSC'-provided 'Campana' test WiFi network.