CovalentStealer is a custom data exfiltration tool observed by CISA during an intrusion affecting a Defense Industrial Base (DIB) sector organization from November 2021 through January 2022, as documented in alert AA22-277A. CISA assessed that likely multiple APT groups had compromised the victim enterprise network, with some actors maintaining long-term access. The tool was used from late July through mid-October 2021 to exfiltrate remaining sensitive files, including sensitive contract-related information collected from shared drives. Reported functionality includes identifying and enumerating file shares, categorizing files, encrypting collected data with a 256-bit AES key, and uploading the files to remote infrastructure. The content states that collected files were stored in a Microsoft OneDrive cloud folder. In the broader intrusion, actors also used compromised credentials, Microsoft Exchange access, Windows Command Shell, PowerShell, WinRAR for manual collection and archiving, and the open-source Impacket toolkit for remote execution and lateral movement. CovalentStealer is therefore associated with APT activity targeting a DIB organization and was specifically used for theft of sensitive enterprise data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.