Threat group.View on attack.mitre.org
MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus.
| Technique | Procedure example |
|---|---|
| T1027.002 Software Packing |
MoustachedBouncer has used malware plugins packed with Themida. |
| T1059.001 PowerShell |
MoustachedBouncer has used plugins to execute PowerShell scripts. |
| T1059.007 JavaScript |
MoustachedBouncer has used JavaScript to deliver malware hosted on HTML pages. |
| T1068 Exploitation for Privilege Escalation |
MoustachedBouncer has exploited CVE-2021-1732 to execute malware components with elevated rights. |
| T1074.002 Remote Data Staging |
MoustachedBouncer has used plugins to save captured screenshots to `.\AActdata\` on an SMB share. |
| T1090 Proxy |
MoustachedBouncer has used a reverse proxy tool similar to the GitHub repository revsocks. |
| T1113 Screen Capture |
MoustachedBouncer has used plugins to take screenshots on targeted systems. |
| T1659 Content Injection |
MoustachedBouncer has injected content into DNS, HTTP, and SMB replies to redirect specifically-targeted victims to a fake Windows Update page to download malware. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.