Disco is a malware framework associated with the Belarus-aligned cyber-espionage actor MoustachedBouncer and has been in use since at least 2020. It is primarily used in surveillance operations targeting foreign diplomatic entities in Belarus and is notable for being delivered through adversary-in-the-middle operations conducted at the ISP level. In these intrusions, victims are induced to execute malicious archive or installer files presented as software updates, after which Disco establishes persistence and retrieves additional components over SMB.
Disco is principally a Go-based implant ecosystem, with related components also implemented in .NET. Its initial stage can create a scheduled task that runs at very short intervals to maintain persistence and repeatedly launch follow-on payloads. The framework is modular and supports execution of spying plugins used to collect victim data and exfiltrate it. Documented plugin capabilities include screenshot capture, execution of PowerShell scripts, reverse-proxy functionality, and use of a local privilege escalation exploit for CVE-2021-1732. Disco operations also include SMB-based staging and exfiltration workflows, reducing dependence on conventional internet-facing command-and-control infrastructure. Associated activity indicates use of multiple communications mechanisms across the broader toolset and operational chain, including DNS and SMB.
Disco forms part of MoustachedBouncer’s newer intrusion stack alongside the older NightClub framework. It has been observed in campaigns that rely on traffic interception and selective redirection to malicious update lures, followed by user execution of malicious ZIP and MSI-delivered payloads. The malware’s role in these operations is post-compromise espionage, plugin execution, persistence, and data theft from Windows systems used by diplomatic targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Disco Go 2020 AitM Disco Execute Spying plugins Exfiltrate Collected data ... Recent file stealer Take screenshots PowerShell scripts LPE CVE-2021-1732 Plug-ins Reverse Proxy (revsocks)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Disco Go 2020 AitM Disco Execute Spying plugins Exfiltrate Collected data ... Recent file stealer Take screenshots PowerShell scripts LPE CVE-2021-1732 Plug-ins Reverse Proxy (revsocks)
16 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
PowerShell scripts ... Government staff Europe and Asia ... Backdoor PowerShell
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage implant/toolset (notably Go/.NET components) delivered via ISP-level adversary-in-the-middle redirection to a fake Windows Update site. Establishes persistence via scheduled tasks and pulls additional payloads/plugins over SMB shares that are themselves intercepted/injected via AitM. Plugins include screenshotting, PowerShell execution, reverse proxying, and privilege escalation support.
Backdoor that persists by creating a scheduled task running every minute.
Malware executed through malicious ZIP and MSI files requiring user interaction.
Malware executed through malicious ZIP and MSI files requiring user interaction.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.