QuietSieve is a stealer malware family identified by Microsoft Threat Intelligence Center (MSTIC) in 2022 as distinct from the related loader PowerPunch. Reported capabilities include collecting files from compromised hosts, identifying and searching removable drives and networked drives for specific file name extensions, executing payloads in a hidden window, checking command-and-control connectivity by pinging 8.8.8.8, and taking screenshots every five minutes. The screenshots are saved locally under the user’s Application Data Temp\SymbolSourceSymbols\icons or Temp\ModeAuto\icons directories. The content also references the Microsoft detection name Trojan:MSIL/QuietSieve from March 2022. High-confidence behaviors directly mentioned are file collection, removable-media and network-drive searching, hidden-window payload execution, periodic screenshot capture, and basic connectivity testing.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2022, the Microsoft Threat Intelligence Center (MSTIC) categorised these payloads as distinct families, notably PowerPunch (a loader) and QuietSieve (a stealer).
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Multiple actors and malware check for internet/network connectivity using ping, tracert, HTTP GET requests, or contacting well-known domains (e.g., google[.]com, bing[.]com, 8.8.8.8) prior to tool transfer or C2 establishment.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.
"Agent Tesla can capture screenshots of the victim’s desktop"; "AppleSeed can take screenshots on a compromised host"; "APT28 has used tools to take screenshots from victims"; "Cobalt Strike's Beacon payload is capable of capturing screenshots"; "PowerSploit's Get-TimedScreenshot Exfiltration module can take screenshots at regular intervals"; "Hydraq includes a component based on the code of VNC that can stream a live feed of the desktop"
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer family name used by MSTIC for a Gamaredon exfiltration component; the report aligns it under the GammaSteel taxonomy.
Malware that verifies C2/network connectivity by pinging 8.8.8.8.
Backdoor that identifies removable drives and searches them for files with specific extensions.
Malware used to identify and search removable drives for files matching specific extensions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.