Disco

S1088

Malware.View on attack.mitre.org

About this malware

Disco is a custom implant that has been used by MoustachedBouncer since at least 2020 including in campaigns using targeted malicious content injection for initial access and command and control.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1053.005
Scheduled Task

Disco can create a scheduled task to run every minute for persistence.

T1071.002
File Transfer Protocols

Disco can use SMB to transfer files.

T1105
Ingress Tool Transfer

Disco can download files to targeted systems via SMB.

T1204.002
Malicious File

Disco has been executed through inducing user interaction with malicious .zip and .msi files.

T1659
Content Injection

Disco has achieved initial access and execution through content injection into DNS, HTTP, and SMB replies to targeted hosts that redirect them to download malicious files.

Groups that use it1

Campaigns0

None recorded.

References1

  1. MoustachedBouncer ESET August 2023 Open source
    Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.