ATT&CKGroupsMoustachedBouncer

MoustachedBouncer

G1019

Threat group.View on attack.mitre.org

About this group

MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1027.002
Software Packing

MoustachedBouncer has used malware plugins packed with Themida.

T1059.001
PowerShell

MoustachedBouncer has used plugins to execute PowerShell scripts.

T1059.007
JavaScript

MoustachedBouncer has used JavaScript to deliver malware hosted on HTML pages.

T1068
Exploitation for Privilege Escalation

MoustachedBouncer has exploited CVE-2021-1732 to execute malware components with elevated rights.

T1074.002
Remote Data Staging

MoustachedBouncer has used plugins to save captured screenshots to `.\AActdata\` on an SMB share.

T1090
Proxy

MoustachedBouncer has used a reverse proxy tool similar to the GitHub repository revsocks.

T1113
Screen Capture

MoustachedBouncer has used plugins to take screenshots on targeted systems.

T1659
Content Injection

MoustachedBouncer has injected content into DNS, HTTP, and SMB replies to redirect specifically-targeted victims to a fake Windows Update page to download malware.

Software3

Campaigns0

None recorded.

References1

  1. MoustachedBouncer ESET August 2023 Open source
    Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.