MoustachedBouncer is a cyber-espionage threat actor aligned with Belarusian state interests and best known for surveillance of foreign diplomats in Belarus. The group has been assessed as leveraging adversary-in-the-middle operations at the ISP level, likely enabled by national network visibility and interception capabilities, to tamper with victim network traffic and deliver malware. Known aliases include Storm-1125 and the misspelling MoushtachedBouncer. The actor has used traffic interception against legitimate software update and connectivity-check workflows to stage malware delivery. Malware associated with the group includes NightClub, an older modular C++ espionage platform active since at least 2014, and Disco, a Go-based implant observed since 2020. These toolsets support modular surveillance and data theft, including plugin-based collection, screenshot capture, keylogging, audio recording, file theft, and exfiltration. Reported command-and-control and data movement channels include email protocols, DNS, and SMB. NightClub has also included a DNS-tunneling backdoor, while more recent tooling has supported PowerShell execution, reverse-proxy functionality, and exploitation of local privilege-escalation vulnerabilities. MoustachedBouncer’s operations are focused on intelligence collection rather than disruption or monetization. Its targeting has centered on diplomatic and government-related personnel, particularly foreign diplomatic missions operating in Belarus. Reporting also notes overlap with Winter Vivern in infrastructure patterns and targeting of government staff in Europe and Asia, but the strongest high-confidence characterization of MoustachedBouncer is as a Belarus-aligned espionage actor conducting network interception-enabled surveillance against diplomatic targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Executes C:\Users\Public\driverpack\driverpackUpdate.exe (the plugin above) using elevated rights via CVE-2021-1732.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The following analytic detects when su runs from a page-cache-corrupted binary... This activity is significant because it indicates a possible privilege escalation attempt, allowing a user to gain root access... CVE CVE-2026-31431 ... References ... copy-fail-CVE-2026-31431
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Mentioned only as an annotation/tag associated with a privilege escalation detection.
Mentioned only as an annotated threat actor associated with the detection content; no campaign or activity by the group is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.