Malware.View on attack.mitre.org
Small Sieve is a Telegram Bot API-based Python backdoor that has been distributed using a Nullsoft Scriptable Install System (NSIS) Installer; it has been used by MuddyWater since at least January 2022.
Security researchers have also noted Small Sieve's use by UNC3313, which may be associated with MuddyWater.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Small Sieve can obtain the IP address of a victim host. |
| T1027 Obfuscated Files or Information |
Small Sieve has the ability to use a custom hex byte swapping encoding scheme combined with an obfuscated Base64 function to protect program strings and Telegram credentials. |
| T1033 System Owner/User Discovery |
Small Sieve can obtain the id of a logged in user. |
| T1036.005 Match Legitimate Resource Name or Location |
Small Sieve can use variations of Microsoft and Outlook spellings, such as "Microsift", in its file names to avoid detection. |
| T1059.003 Windows Command Shell |
Small Sieve can use `cmd.exe` to execute commands on a victim's system. |
| T1059.006 Python |
Small Sieve can use Python scripts to execute commands. |
| T1071.001 Web Protocols |
Small Sieve can contact actor-controlled C2 servers by using the Telegram API over HTTPS. |
| T1102.002 Bidirectional Communication |
Small Sieve has the ability to use the Telegram Bot API from Telegram Messenger to send and receive messages. |
| T1105 Ingress Tool Transfer |
Small Sieve has the ability to download files. |
| T1132.002 Non-Standard Encoding |
Small Sieve can use a custom hex byte swapping encoding scheme to obfuscate tasking traffic. |
| T1480 Execution Guardrails |
Small Sieve can only execute correctly if the word `Platypus` is passed to it on the command line. |
| T1547.001 Registry Run Keys / Startup Folder |
Small Sieve has the ability to add itself to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OutlookMicrosift` for persistence. |
| T1573.002 Asymmetric Cryptography |
Small Sieve can use SSL/TLS for its HTTPS Telegram Bot API-based C2 channel. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.