Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 16:28:09 UTC Home > List all groups > MoustachedBouncer APT group: MoustachedBouncer Names MoustachedBouncer (ESET) Country Belarus Motivation Information theft and espionage First seen 2014 Description (ESET) MoustachedBouncer is a cyberespionage group discovered by ESET Research and first publicly disclosed in this blogpost. The group has been active since at least 2014 and only targets foreign embassies in Belarus. Since 2020, MoustachedBouncer has most likely been able to perform adversary-in-the-middle (AitM) attacks at the ISP level, within Belarus, in order to compromise its targets. The group uses two separate toolsets that we have named NightClub and Disco. While we track MoustachedBouncer as a separate group, we have found elements that make us assess with low confidence that they are closely collaborating with another group known as Winter Vivern. Observed Sectors: Foreign embassies in Belarus. Countries: Belarus. Tools used Information Last change to this card: 06 September 2023 Download this actor card in PDF or JSON format Source: https://apt.etda.or.th/cgi-bin/showcard.cgi?u=e6ac692d-4adb-403d-83c6-f0d8845a4866 https://apt.etda.or.th/cgi-bin/showcard.cgi?u=e6ac692d-4adb-403d-83c6-f0d8845a4866 Page 1 of 1