Small Sieve can obtain the IP address of a victim host.4
tool
Small Sieve S1035
- Type
- malware
- Platform
- Windows
- Created
- 16 August 2022
- Last modified
- 16 April 2025
Small Sieve is a Telegram Bot API-based Python backdoor that has been distributed using a Nullsoft Scriptable Install System (NSIS) Installer; it has been used by MuddyWater since at least January 2022.[1][2]
Security researchers have also noted Small Sieve's use by UNC3313, which may be associated with MuddyWater.[3]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S1035
Small Sieve has the ability to use a custom hex byte swapping encoding scheme combined with an obfuscated Base64 function to protect program strings and Telegram credentials.5
Small Sieve can obtain the id of a logged in user.6
Small Sieve can use variations of Microsoft and Outlook spellings, such as "Microsift", in its file names to avoid detection.7
Small Sieve can use cmd.exe to execute commands on a victim's system.8
Small Sieve can use Python scripts to execute commands.9
Standing S1035
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
57th percentile · 57% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
53rd percentile · 53% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
68th percentile · 68% of 825 ATT&CK software entries have this many detection rules per technique or fewer.
Detection coverage S1035
508 distinct rules cover the 13 techniques recorded for this tool. The 534 technique-to-rule mappings resolve to 508 distinct rules, because one rule can cover several techniques. 388 Sigma · 120 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org