NEW: Group Profiler — instant APT intel lookup. Try it →

MoustachedBouncer

G1019 Espionage MITRE ATT&CK →

Overview

MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus.

Naming & attribution

MoustachedBouncer is tracked under 1 names across the industry. It uses 8 documented ATT&CK techniques — more than 24% of the 174 groups tracked here. Activity attributed since at least 2014.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1659 Content Injection — used by 1 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Saint Bear Russia — 3 shared techniques (13% overlap)
  • FIN6 — 4 shared techniques (9% overlap)
  • Silence — 3 shared techniques (9% overlap)
  • Winter Vivern Russia — 3 shared techniques (9% overlap)
  • Cobalt Group — 3 shared techniques (8% overlap)
  • TA505 — 3 shared techniques (8% overlap)

Targets

Government

Regions

Eastern Europe · Europe · Northeast Africa · South Asia

Capabilities

  • Custom malware/implant development — ATT&CK: 3 attributed custom malware families

TTPs — 8 techniques across 6 tactics

Initial Access

Execution

Privilege Escalation

Stealth

Collection

Command and Control

Tools & malware (3)

NightClub · Disco · SharpDisco

Reporting (1)