Disco is a malware framework used by the cyberespionage group MoustachedBouncer, which has been active since at least 2014 and targets foreign embassies in Belarus. According to ESET, MoustachedBouncer began using Disco in parallel with its older NightClub framework starting in 2020. Disco is associated with ISP-level adversary-in-the-middle operations in Belarus that tamper with Windows captive portal checks and redirect victims to a fake Windows Update page at updates.microsoft[.]com, where users are prompted to download a malicious installer. Execution has also been observed through user interaction with malicious .zip and .msi files.
Observed Disco delivery includes MicrosoftUpdate845255.zip containing MicrosoftUpdate845255.exe, a Go-based Disco dropper (SHA-1: E65EB4467DDB1C99B09AE87BA0A964C36BAB4C30), and an earlier C# dropper, SharpDisco (SHA-1: A3AE82B19FEE2756D6354E85A094F1A4598314AB), downloaded as EdgeUpdate.exe. For persistence, Disco can create scheduled tasks that run every minute. ESET specifically observed a scheduled task executing \35.214.56[.]2\OfficeBroker\OfficeBroker.exe every minute, and SharpDisco creating scheduled tasks implementing SMB-based reverse shells using \24.9.51[.]94\EDGEUPDATE\EDGEAIN/EDGEAOUT and EDGEBIN/EDGEBOUT. Additional SMB servers observed in the operation included \209.19.37[.]184, \38.9.8[.]78, and \59.6.8[.]25.
Disco uses SMB shares for staging and data exfiltration, reducing reliance on internet-reachable command-and-control infrastructure. Reported plugin capabilities include screenshot capture, PowerShell execution, a reverse proxy inspired by revsocks, and a local privilege escalation exploit leveraging CVE-2021-1732. The dropper also performs DNS queries for windows.system.update[.]com, interpreted by ESET as a likely compromise beacon, while SharpDisco issued a DNS request for edgeupdate-security-windows[.]com as a likely success signal. The activity was observed on Belarus ISP networks including Unitary Enterprise A1 and Beltelecom.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Starting in 2020, the group has been using, in parallel, a second malware framework we have named Disco.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Starting in 2020, the group has been using, in parallel, a second malware framework we have named Disco.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage implant/toolset (notably Go/.NET components) delivered via ISP-level adversary-in-the-middle redirection to a fake Windows Update site. Establishes persistence via scheduled tasks and pulls additional payloads/plugins over SMB shares that are themselves intercepted/injected via AitM. Plugins include screenshotting, PowerShell execution, reverse proxying, and privilege escalation support.
Backdoor that persists by creating a scheduled task running every minute.
Malware executed through malicious ZIP and MSI files requiring user interaction.
Malware executed through malicious ZIP and MSI files requiring user interaction.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.