Small Sieve, also known as GRAMDOOR, is a Python-based Windows backdoor used by MuddyWater, an Iranian cyberespionage group subordinate to Iran’s Ministry of Intelligence and Security. It is distributed through a Nullsoft Scriptable Install System (NSIS) installer, with analyzed payloads packaged using PyInstaller and Python 3.9. The installer establishes persistence through a per-user Windows Registry Run entry. Small Sieve forms part of MuddyWater’s malware arsenal used in operations against government and private-sector organizations, including telecommunications, defense, local government, and oil and natural gas.
The backdoor uses the Telegram Bot API over HTTPS for beaconing, receiving commands, and returning results. Its functionality includes identifying the logged-in user, downloading files, executing commands through the Windows command shell, changing its Telegram authentication token, and disconnecting. It applies custom byte-shuffling and string-encoding routines, including Base64 and a custom alphabet, to obscure communications and stored configuration. Malicious components masquerade as Microsoft, Outlook, or Windows Defender-related artifacts, sometimes using misspelled product names. Execution requires a specific command-line argument, providing an execution guardrail. An analyzed termination command stops the backdoor without removing its persistence mechanism.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Small Sieve is a simple Python backdoor distributed using a Nullsoft Scriptable Install System (NSIS) installer, gram_app.exe.
"Mandiant has named this backdoor GRAMDOOR due to its ability to use the Telegram Bot API for communication."
17 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
These actors also maintain persistence on victim networks via tactics such as side-loading dynamic link libraries, to trick legitimate programs into running malware and obfuscating PowerShell scripts to hide command and control functions.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
It says the Small Sieve's beacons and tasking are performed using Telegram API.
APT41 DUST used HTTPS for command and control. APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS. Lumma Stealer has used HTTPS for command and control purposes.
Small Sieve’s beacons and taskings are performed using Telegram API over Hypertext Transfer Protocol Secure (HTTPS) [T1071.001], and the tasking and beaconing data is obfuscated through a hex byte swapping encoding scheme combined with an obfuscated Base64 function [T1027], T1132.002].
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Python backdoor installed via an NSIS installer that establishes persistence through a registry run key and uses custom obfuscation plus the Telegram Bot API for beaconing and tasking.
Backdoor associated in the content with Telegram Bot API traffic from internal hosts.
Previously used MuddyWater malware family mentioned as historical background.
A MuddyWater-associated malware/tool documented in U.S. government advisory AA22-055A.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.