MoustachedBouncer

🔴 High
Also known as: MoustachedBouncer, Storm-1125

MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus. MoustachedBouncer ESET August 2023

🌍 Country Belarus
Risk Level High
🎯 Incident Type Espionage
🧭 ATT&CK G1019
Government

Introduction

MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus. MoustachedBouncer ESET August 2023

Activities and Tactics

Targeted Sectors: Government

Country of Origin: 🏳️ Belarus

Risk Level: High

Incident Type: Espionage

Suspected Victims: Europe, Eastern Europe, South Asia, Northeast Africa

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • CyberGate
  • Cyber Eye RAT

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: Belarus Additional attribution information pending cataloguing.

References

[1] mitre-attack [2] MoustachedBouncer ESET August 2023 Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.