Small Sieve is a Telegram Bot API-based Python backdoor that has been distributed using a Nullsoft Scriptable Install System (NSIS) Installer; it has been used by MuddyWater since at least January 2022.[1][2]
Security researchers have also noted Small Sieve's use by UNC3313, which may be associated with MuddyWater.[3]
| Name | Description |
|---|---|
| GRAMDOOR |
| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1036 | .005 | 伪装: Match Legitimate Name or Location |
Small Sieve can use variations of Microsoft and Outlook spellings, such as "Microsift", in its file names to avoid detection.[2] |
| Enterprise | T1573 | .002 | 加密通道: Asymmetric Cryptography |
Small Sieve can use SSL/TLS for its HTTPS Telegram Bot API-based C2 channel.[1] |
| Enterprise | T1547 | .001 | 启动或登录自动启动执行: Registry Run Keys / Startup Folder |
Small Sieve has the ability to add itself to |
| Enterprise | T1059 | .003 | 命令与脚本解释器: Windows Command Shell |
Small Sieve can use |
| .006 | 命令与脚本解释器: Python |
Small Sieve can use Python scripts to execute commands.[2] |
||
| Enterprise | T1071 | .001 | 应用层协议: Web Protocols |
Small Sieve can contact actor-controlled C2 servers by using the Telegram API over HTTPS.[1] |
| Enterprise | T1480 | 执行保护 |
Small Sieve can only execute correctly if the word |
|
| Enterprise | T1132 | .002 | 数据编码: Non-Standard Encoding |
Small Sieve can use a custom hex byte swapping encoding scheme to obfuscate tasking traffic.[1][2] |
| Enterprise | T1027 | 混淆文件或信息 |
Small Sieve has the ability to use a custom hex byte swapping encoding scheme combined with an obfuscated Base64 function to protect program strings and Telegram credentials.[2] |
|
| Enterprise | T1033 | 系统所有者/用户发现 |
Small Sieve can obtain the id of a logged in user.[2] |
|
| Enterprise | T1016 | 系统网络配置发现 |
Small Sieve can obtain the IP address of a victim host.[2] |
|
| Enterprise | T1102 | .002 | 网络服务: Bidirectional Communication |
Small Sieve has the ability to use the Telegram Bot API from Telegram Messenger to send and receive messages.[2] |
| Enterprise | T1105 | 输入工具传输 |
Small Sieve has the ability to download files.[2] |
|
| ID | Name | References |
|---|---|---|
| G0069 | MuddyWater |