ATT&CKSoftwareQuietSieve

QuietSieve

S0686

Malware.View on attack.mitre.org

About this malware

QuietSieve is an information stealer that has been used by Gamaredon Group since at least 2021.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1005
Data from Local System

QuietSieve can collect files from a compromised host.

T1016.001
Internet Connection Discovery

QuietSieve can check C2 connectivity with a `ping` to 8.8.8.8 (Google public DNS).

T1071.001
Web Protocols

QuietSieve can use HTTPS in C2 communications.

T1083
File and Directory Discovery

QuietSieve can search files on the target host by extension, including doc, docx, xls, rtf, odt, txt, jpg, pdf, rar, zip, and 7z.

T1105
Ingress Tool Transfer

QuietSieve can download and execute payloads on a target host.

T1113
Screen Capture

QuietSieve has taken screenshots every five minutes and saved them to the user's local Application Data folder under `Temp\SymbolSourceSymbols\icons` or `Temp\ModeAuto\icons`.

T1120
Peripheral Device Discovery

QuietSieve can identify and search removable drives for specific file name extensions.

T1135
Network Share Discovery

QuietSieve can identify and search networked drives for specific file name extensions.

T1564.003
Hidden Window

QuietSieve has the ability to execute payloads in a hidden window.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Microsoft Actinium February 2022 Open source
    Microsoft Threat Intelligence Center. (2022, February 4). ACTINIUM targets Ukrainian organizations. Retrieved February 18, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.