ATT&CKSoftwareSmall Sieve

Small Sieve

S1035

Malware.View on attack.mitre.org

About this malware

Small Sieve is a Telegram Bot API-based Python backdoor that has been distributed using a Nullsoft Scriptable Install System (NSIS) Installer; it has been used by MuddyWater since at least January 2022.

Security researchers have also noted Small Sieve's use by UNC3313, which may be associated with MuddyWater.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1016
System Network Configuration Discovery

Small Sieve can obtain the IP address of a victim host.

T1027
Obfuscated Files or Information

Small Sieve has the ability to use a custom hex byte swapping encoding scheme combined with an obfuscated Base64 function to protect program strings and Telegram credentials.

T1033
System Owner/User Discovery

Small Sieve can obtain the id of a logged in user.

T1036.005
Match Legitimate Resource Name or Location

Small Sieve can use variations of Microsoft and Outlook spellings, such as "Microsift", in its file names to avoid detection.

T1059.003
Windows Command Shell

Small Sieve can use `cmd.exe` to execute commands on a victim's system.

T1059.006
Python

Small Sieve can use Python scripts to execute commands.

T1071.001
Web Protocols

Small Sieve can contact actor-controlled C2 servers by using the Telegram API over HTTPS.

T1102.002
Bidirectional Communication

Small Sieve has the ability to use the Telegram Bot API from Telegram Messenger to send and receive messages.

T1105
Ingress Tool Transfer

Small Sieve has the ability to download files.

T1132.002
Non-Standard Encoding

Small Sieve can use a custom hex byte swapping encoding scheme to obfuscate tasking traffic.

T1480
Execution Guardrails

Small Sieve can only execute correctly if the word `Platypus` is passed to it on the command line.

T1547.001
Registry Run Keys / Startup Folder

Small Sieve has the ability to add itself to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OutlookMicrosift` for persistence.

T1573.002
Asymmetric Cryptography

Small Sieve can use SSL/TLS for its HTTPS Telegram Bot API-based C2 channel.

Groups that use it1

Campaigns0

None recorded.

References3

  1. DHS CISA AA22-055A MuddyWater February 2022 Open source
    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.
  2. Mandiant UNC3313 Feb 2022 Open source
    Tomcik, R. et al. (2022, February 24). Left On Read: Telegram Malware Spotted in Latest Iranian Cyber Espionage Activity. Retrieved August 18, 2022.
  3. NCSC GCHQ Small Sieve Jan 2022 Open source
    NCSC GCHQ. (2022, January 27). Small Sieve Malware Analysis Report. Retrieved August 22, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.