ATT&CKReferencesNCSC GCHQ Small Sieve Jan 2022

NCSC GCHQ Small Sieve Jan 2022

NCSC GCHQ. (2022, January 27). Small Sieve Malware Analysis Report. Retrieved August 22, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareSmall Sieve

Small Sieve can obtain the IP address of a victim host.

T1027
Obfuscated Files or Information
MalwareSmall Sieve

Small Sieve has the ability to use a custom hex byte swapping encoding scheme combined with an obfuscated Base64 function to protect program strings and Telegram credentials.

T1033
System Owner/User Discovery
MalwareSmall Sieve

Small Sieve can obtain the id of a logged in user.

T1036.005
Match Legitimate Resource Name or Location
MalwareSmall Sieve

Small Sieve can use variations of Microsoft and Outlook spellings, such as "Microsift", in its file names to avoid detection.

T1059.003
Windows Command Shell
MalwareSmall Sieve

Small Sieve can use `cmd.exe` to execute commands on a victim's system.

T1059.006
Python
MalwareSmall Sieve

Small Sieve can use Python scripts to execute commands.

T1102.002
Bidirectional Communication
MalwareSmall Sieve

Small Sieve has the ability to use the Telegram Bot API from Telegram Messenger to send and receive messages.

T1105
Ingress Tool Transfer
MalwareSmall Sieve

Small Sieve has the ability to download files.

T1132.002
Non-Standard Encoding
MalwareSmall Sieve

Small Sieve can use a custom hex byte swapping encoding scheme to obfuscate tasking traffic.

T1480
Execution Guardrails
MalwareSmall Sieve

Small Sieve can only execute correctly if the word `Platypus` is passed to it on the command line.

T1547.001
Registry Run Keys / Startup Folder
MalwareSmall Sieve

Small Sieve has the ability to add itself to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OutlookMicrosift` for persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.