MoustachedBouncer is a Belarus-linked nation-state cyberespionage group known for ISP-level AitM attacks and targeting foreign embassies.
Analyst brief
MoustachedBouncer is a Belarus-linked nation-state cyberespionage group active since at least 2014. The group primarily targets foreign embassies in Belarus, extending its operations to government sectors in Europe, Eastern Europe, South Asia, and Northeast Africa. Key TTPs include Adversary-in-the-Middle (AitM) attacks at the ISP level, initial access via Content Injection (T1659), execution with PowerShell/JavaScript, and the use of custom malware sets named NightClub, Disco, and SharpDisco. Defenders should focus on detecting anomalous network traffic (especially proxy-based C2), unauthorized PowerShell execution, and potential ISP-level traffic manipulation.
MoustachedBouncer
nation-state
MoustachedBouncer is a cyberespionage group discovered by ESET Research and first publicly disclosed in August 2023. The group has been active since at least 2014 and only targets foreign embassies in Belarus. Since 2020, MoustachedBouncer has most likely been able to perform adversary-in-the-middle (AitM) attacks at the ISP level, within Belarus, in order to compromise its targets. The group uses two separate toolsets that we have named NightClub and Disco.
origin (suspected)
🇧🇾Belarus· state-sponsoredattribution confidence: medium (50)