Malware.View on attack.mitre.org
QuietSieve is an information stealer that has been used by Gamaredon Group since at least 2021.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
QuietSieve can collect files from a compromised host. |
| T1016.001 Internet Connection Discovery |
QuietSieve can check C2 connectivity with a `ping` to 8.8.8.8 (Google public DNS). |
| T1071.001 Web Protocols |
QuietSieve can use HTTPS in C2 communications. |
| T1083 File and Directory Discovery |
QuietSieve can search files on the target host by extension, including doc, docx, xls, rtf, odt, txt, jpg, pdf, rar, zip, and 7z. |
| T1105 Ingress Tool Transfer |
QuietSieve can download and execute payloads on a target host. |
| T1113 Screen Capture |
QuietSieve has taken screenshots every five minutes and saved them to the user's local Application Data folder under `Temp\SymbolSourceSymbols\icons` or `Temp\ModeAuto\icons`. |
| T1120 Peripheral Device Discovery |
QuietSieve can identify and search removable drives for specific file name extensions. |
| T1135 Network Share Discovery |
QuietSieve can identify and search networked drives for specific file name extensions. |
| T1564.003 Hidden Window |
QuietSieve has the ability to execute payloads in a hidden window. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.