MoustachedBouncer
Overview
MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus.
Naming & attribution
MoustachedBouncer is tracked under 1 names across the industry. It uses 8 documented ATT&CK techniques — more than 24% of the 174 groups tracked here. Activity attributed since at least 2014.
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1659Content Injection — used by 1 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Saint Bear Russia — 3 shared techniques (13% overlap)
- FIN6 — 4 shared techniques (9% overlap)
- Silence — 3 shared techniques (9% overlap)
- Winter Vivern Russia — 3 shared techniques (9% overlap)
- Cobalt Group — 3 shared techniques (8% overlap)
- TA505 — 3 shared techniques (8% overlap)
Targets
Government
Regions
Eastern Europe · Europe · Northeast Africa · South Asia
Capabilities
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 8 techniques across 6 tactics
Initial Access
-
T1659Content Injection
Execution
-
T1059.001PowerShell -
T1059.007JavaScript
Privilege Escalation
Stealth
-
T1027.002Software Packing
Collection
-
T1074.002Remote Data Staging -
T1113Screen Capture
Command and Control
-
T1090Proxy
Tools & malware (3)
NightClub · Disco · SharpDisco