MoustachedBouncer

MITRE ATT&CK: G1019 View on attack.mitre.org

Aliases: MoustachedBouncer

First seen
2014-01-01 00:00:00
Origin
BY
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Profile updated
2026-07-07 12:04:30

Targeted industries: government-and-public-sector

Targeted regions: country_code:by

Context

MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus.

Detection coverage

  • 1 YARA rules
  • 247 Sigma rules

Malware & tools used

  • PowerShell (attack-pattern)
  • JavaScript (attack-pattern)
  • Software Packing (attack-pattern)
  • Screen Capture (attack-pattern)
  • Proxy (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Remote Data Staging (attack-pattern)
  • Content Injection (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • SharpDisco (malware)
  • NightClub (malware)
  • Disco (malware)

Reports & references

  • ESET — Moustachedbouncer Espionage Against Foreign Diplomats In Belarus (report)
  • MITRE ATT&CK — G1019 (report)

External references