NightClub is a modular Windows espionage malware framework associated with the Belarus-aligned threat actor MoustachedBouncer and active since at least 2014. It is a long-running surveillance platform used primarily against foreign diplomatic targets in Belarus. The malware has evolved across multiple generations from an early service-based implant into a plugin-driven framework with email-based command and control and specialized collection modules.
NightClub is written in C++ and uses SMTP and IMAP for command-and-control communications, with some variants also supporting DNS-based communications and exfiltration. Document theft is a core function, with collection focused on common office and PDF formats. Reported plugins and modules provide keylogging, screenshot capture, audio recording, active-window enumeration, removable-drive monitoring, and a DNS-tunneling backdoor. Screen capture functionality has been implemented through Windows graphics APIs, while audio capture has leveraged components such as the LAME encoder and mciSendStringW.
The malware uses multiple persistence and evasion techniques on Windows. Known variants establish persistence through Windows services and by modifying service-related Registry configuration, including ServiceDLL settings. Operators have used legitimate-looking service and executable names to blend into the host environment. NightClub has also staged captured files and keystrokes locally before exfiltration and has manipulated file timestamps to match legitimate Windows files as an anti-forensics measure.
Operationally, NightClub has been used as part of MoustachedBouncer’s broader cyber-espionage activity targeting embassy personnel and other foreign diplomatic entities. Later variants used modular orchestrator and agent components with external encrypted configuration, reflecting continued development and operational maturity. Overall, NightClub is best characterized as a stealthy surveillance backdoor designed for long-term collection on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Recent file stealer Take screenshots PowerShell scripts LPE CVE-2021-1732 Plug-ins Reverse Proxy (revsocks)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
3: NightClub ... NightClub C++ 2014 VPN ... File stealer .doc, .docx, .xls and .pdf ... C&C by emails SMTP ... NightClub plugins ... Audio recorder Screenshotter Keylogger DNS-tunneling backdoor
26 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Catchamas creates three Registry keys to establish persistence by adding a Windows Service ... TEARDROP modified the Registry to create a Windows service for itself ... NightClub can modify the Registry to set the ServiceDLL for a service created by the malware for persistence.
InvisiMole can collect data from the system, and can monitor changes in specified directories. NightClub can use a file monitor to steal specific files from targeted systems.
Agent Tesla can achieve persistence by modifying Registry key entries. Attor's dispatcher can modify the Run registry key. Kimsuky has also modified the registry entry for HKCU:\Software\Microsoft\Windows\CurrentVersion\Run registry key for persistence with the name WindowsSecurityCheck. PLAINTEE uses reg add to add a Registry Run key for persistence.
Catchamas creates three Registry keys to establish persistence by adding a Windows Service ... TEARDROP modified the Registry to create a Windows service for itself ... NightClub can modify the Registry to set the ServiceDLL for a service created by the malware for persistence.
InvisiMole can collect data from the system, and can monitor changes in specified directories. NightClub can use a file monitor to steal specific files from targeted systems.
Agent Tesla can achieve persistence by modifying Registry key entries. Attor's dispatcher can modify the Run registry key. Kimsuky has also modified the registry entry for HKCU:\Software\Microsoft\Windows\CurrentVersion\Run registry key for persistence with the name WindowsSecurityCheck. PLAINTEE uses reg add to add a Registry Run key for persistence.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Multiple malware families are described as identifying/enumerating open windows or capturing foreground window titles (e.g., via EnumWindows, GetForegroundWindow, GetWindowText) to understand user activity and provide context for keylogging/screencapture.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that aligns malicious DLL timestamps with legitimate Windows DLLs for stealth.
Modular C++ espionage implant framework used for embassy targeting. Uses email (SMTP/IMAP) for C2 and exfiltration, supports plugin delivery (e.g., keylogger, screenshotter, audio recorder, file monitor/stealer), and includes a DNS-tunneling backdoor module in later versions. Persists via Windows services and uses encrypted/externally stored configuration in newer variants.
Malware that creates a Windows service named WmdmPmSp for persistence.
Backdoor that loads a module using LAME encoder and mciSendStringW to control and capture audio.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.