Overview 11 indicators
MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus.
| ipv4 | 6 | G1019.json |
| domain | 5 | G1019-domain.txt |
Techniques 9 ATT&CK
Open in ATT&CK Navigator → or download the layer (9 techniques, layer 4.5)
- T1027.002 Software Packing
- T1059.001 PowerShell
- T1059.007 JavaScript
- T1068 Exploitation for Privilege Escalation
- T1074.002 Remote Data Staging
- T1090 Proxy
- T1113 Screen Capture
- T1655.001 Match Legitimate Name or Location
- T1659 Content Injection
Software 3
Principal sources 1 reports
Ranked by how many of this actor's indicators each report brought in.
Timeline 11 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
11 shown
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
welivesecurity.com/en/eset-research/moustachedbouncer-espi…
domain centrocspupdate.com domain dervasopssec.com domain edgeupdate-security-windows.com domain ocsp-atomsecure.com domain securityocspdev.com ipv4 209.19.37.184:445 ipv4 24.9.51.94:445 ipv4 35.214.56.2:445 ipv4 38.9.8.78:445 ipv4 52.3.8.25:445 ipv4 59.6.8.25:445