Netskope Threat Labs

Disco

ATP Sandbox Adv. Heuristics

Disco is a custom implant that the MoustachedBouncer threat actor has used since at least 2020, including campaigns that used targeted malicious content injection for initial access and command and control.

First seen
May 2022
Last seen
September 2026

5 techniques across 3 tactics.

TA0001 Initial Access

TA0002 Execution

TA0011 Command and Control

Alert Name
ByteCode-MSIL.Backdoor.Disco
ByteCode-MSIL.Infostealer.Disco
ByteCode-MSIL.Spyware.Disco
MacOS.Backdoor.Disco
MacOS.Infostealer.Disco
Script-JS.Infostealer.Disco
Script-Python.Trojan.Disco
Win32.Infostealer.Disco
Win32.Trojan.Disco
Win64.Infostealer.Disco