MoustachedBouncer
MoustachedBouncer (canonical ESET naming per Matthieu Faou's August 10, 2023 Black Hat USA 2023 conference presentation and WeLiveSecurity research blog disclosure) is a Belarus- aligned cyber-espionage cluster active publicly since at least November 2014 (oldest NightClub sample dates to November 19, 2014), one of the longest-running publicly- tracked Belarus-aligned clusters with operational mission objective operationally narrow to targeting only foreign embassies in Belarus.
ESET assesses with medium confidence Belarus-state-aligned operational interests.
signature adversary-in-the-middle (AitM) operational tradecraft at the internet service provider (ISP) level within Belarus since 2020, operationally requiring access to Belarusian ISP infrastructure practically achievable only through state-aligned cooperation with Belarusian telecommunications providers using SORM (System for Operative Investigative Activities) lawful interception system.
signature NightClub + Disco two-implant operational pattern with Disco used in conjunction with AitM attacks and NightClub used for victims where ISP-level traffic interception isn't possible (e.g., end-to-end encrypted VPN)
both implants support spying plugins (screenshotter, audio recorder, file stealer, keylogger, DNS-tunneling backdoor)
NightClub uses Czech Seznam.cz + Russian Mail.ru webmail services for SMTP + IMAP C&C communications with attackers' own created email accounts.
signature fake Windows Update redirect tradecraft enabled by ISP-level traffic tampering; per ESET telemetry targeted embassy staff of 4-5 countries (two from Europe, one from South Asia, one from Northeast Africa) since June 2017 with documented multi-year repeat targeting (one European diplomat compromised in November 2020 and again in July 2022)
low-confidence operational connection to Winter Vivern based on shared common C&C infrastructure features per ESET.
AitM tradecraft parallel to Turla and StrongPity ISP-level-trojanized-software- installer historical tradecraft.
fills Belarus-aligned foreign-embassy-surveillance specialization cell in the curated corpus, one of the few publicly-tracked Belarus- attributed clusters complementing winter_vivern_ta473's Russia-AND-Belarus dual-aligned tracking.