← threatfilter.dev / all groups / MoustachedBouncer
MoustachedBouncer
Overview
MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus.
Targets
Government
Regions
Eastern Europe · Europe · Northeast Africa · South Asia
Capabilities
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 8 techniques across 6 tactics
Initial Access
-
T1659Content Injection
Execution
-
T1059.001PowerShell -
T1059.007JavaScript
Privilege Escalation
Stealth
-
T1027.002Software Packing
Collection
-
T1074.002Remote Data Staging -
T1113Screen Capture
Command and Control
-
T1090Proxy
Tools & malware (3)
NightClub · Disco · SharpDisco