SharpDisco is a .NET-based malware component within the Disco toolset used by the cyberespionage group MoustachedBouncer, which has targeted foreign embassies in Belarus. It has been observed as an early-stage dropper associated with adversary-in-the-middle operations that redirect victims to fake software-update lures and deliver payloads through SMB-based staging infrastructure.
SharpDisco is designed for stealthy execution and follow-on access. It can hide windows during execution using .NET process settings, create scheduled tasks for repeated execution, and deploy plugins that extend functionality. Documented plugins include a component that monitors external or removable drives and another that exfiltrates stolen files over SMB shares that also serve as command-and-control infrastructure. SharpDisco has also been observed creating scheduled tasks that implement SMB-based reverse-shell style communications by reading from and writing to designated SMB shares.
The malware is part of a broader operational ecosystem in which Disco components rely on SMB for payload staging, command exchange, and data theft, reducing dependence on conventional internet-facing command-and-control servers. MoustachedBouncer’s Disco framework has also been associated with screenshot capture, PowerShell execution, reverse-proxy functionality, and local privilege-escalation tooling elsewhere in the toolset. SharpDisco specifically targets Windows systems and supports espionage-oriented collection and covert post-compromise activity against diplomatic targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In January 2020 we observed a MoustachedBouncer dropper, which we named SharpDisco, being downloaded from https://mail.mfa.gov.<redacted>/EdgeUpdate.exe by a Microsoft Edge process.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Multiple entries describe enumerating local, logical, or physical drives and disk/volume information, e.g., 'can enumerate local drives,' 'GetLogicalDrives,' 'fsutil fsinfo drives,' 'list drives,' and 'discover logical drive information including the drive type, free space, and volume information.'
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that hides windows using ProcessWindowStyle.Hidden.
C# dropper that displays a fake update UI while creating scheduled tasks that implement SMB-based reverse shells (reading commands from and writing output to files on an SMB share). Also performs a DNS beacon to an unregistered domain to signal successful compromise.
Backdoor that creates scheduled tasks to execute reverse shells over SMB shares.
Backdoor that deploys a plugin to monitor external drives.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.