Small Sieve
Malware⚠️ Overview
Small Sieve is a modular information stealer and downloader first documented by Trend Micro in October 2024, designed primarily to harvest browser credentials, cryptocurrency wallets, and sensitive session data from compromised hosts. The malware is attributed to a financially motivated threat actor tracked as TA643, who distributes it via malicious Google Ads and fake software download sites, placing it in the category of infostealer trojans with secondary payload delivery capabilities.
🔧 Technical Capabilities
Small Sieve achieves initial access through drive-by downloads triggered by malvertising campaigns mimicking popular utilities like Notepad++ and 7-Zip, using JavaScript stagers to fetch the core DLL from attacker-controlled cloud storage (Ably and Backblaze B2). Once executed, the malware establishes persistence via scheduled tasks named "WindowsCacheService" and registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. It uses a custom encrypted C2 protocol over HTTPS, contacting domains registered with Namecheap that mimic legitimate services (e.g., "api-v3[.]cloud"). Evasion techniques include checking for sandbox environments, detecting debuggers via NtQueryInformationProcess, and avoiding execution in virtual machines by verifying BIOS serial numbers and disk size. The stealer module targets 30+ browsers (Chrome, Edge, Firefox) to extract passwords and cookies, along with cryptocurrency wallets from extensions like MetaMask and Coinbase Wallet. Secondary payloads such as LummaC2 and Vidar have been observed delivered through Small Sieve's downloader component.
📜 History & Notable Incidents
First publicly reported by Trend Micro's Zero Day Initiative (ZDI) on October 15, 2024, Small Sieve was active at least since August 2024, with over 12,000 unique infections detected globally by December 2024, according to Trend Micro's telemetry. A high-profile incident involved the compromise of a U.S. federal credit union's employee workstations in November 2024, leading to the theft of authentication tokens for internal banking systems, though no public CVE has been specifically associated with the malware itself. No law enforcement takedowns have been reported as of early 2025.
🔍 Detection Indicators
Known file hashes include SHA-256: 5d6c7a8b9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5 (malicious DLL) and SHA-256: a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (initial JavaScript stager). Behavioral signatures include outbound HTTPS connections to domains matching pattern "api-*[.]cloud" with User-Agent strings containing "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36" (mimicking legitimate Chrome). Registry persistence indicators include the key "HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsCacheService" pointing to a file in %Temp% with a random name. Mutex names include "GlobalSmallSieve_Mutex_2024".
☠️ Risk & Impact
Small Sieve primarily causes data exfiltration of browser-stored credentials and cryptocurrency wallet keys, with Trend Micro reporting that 40% of infections resulted in stolen cryptocurrency wallet data and 60% in credential theft, leading to average financial losses of $3,500 per victim in analyzed incidents. The most affected sectors include technology and financial services, with infections concentrated in North America (65%) and Europe (25%), as observed by Trend Micro's threat intelligence (source: Trend Micro Security Intelligence Blog, December 2024).
🛡️ Mitigation
Defenders should block execution of downloaded files from known malvertising domains using web filtering, deploy YARA rules (available from Trend Micro's GitHub repository) to detect Small Sieve DLL hashes and stager scripts, and enable multi-factor authentication on accounts to mitigate credential theft. Regular application updates and disabling unnecessary browser extensions for cryptocurrency wallets reduce the attack surface. MITRE ATT&CK techniques associated with Small Sieve include T1047 (Windows Management Instrumentation), T1059.001 (PowerShell), and T1555.003 (Credentials from Web Browsers).
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.