Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomwareUsed by 1 actor

Grunt

Grunt is an implant associated with the open source Covenant command-and-control framework. The provided content places it in post-exploitation and espionage contexts rather than as a standalone malware family with uniquely described functionality. Mandiant reported that FIN12 intermittently used GRUNT during 2020 as one of several post-exploitation tools alongside Cobalt Strike BEACON, METERPRETER, ANCHOR, and GRIMAGENT after the group’s 2020 hiatus. In separate reporting on Russia-linked APT28/Fancy Bear activity, Zscaler observed a 2026 phishing campaign exploiting CVE-2026-21509, a Microsoft Office/Microsoft 365 vulnerability that bypasses OLE mitigations via malicious RTF documents. In one observed infection chain, exploitation led to download of a malicious dropper DLL, then a previously undocumented loader named PixyNetLoader, which staged additional payloads including a Covenant Grunt implant. That campaign targeted users in Central and Eastern Europe, including Ukraine, Slovakia, and Romania, with lures in Romanian, Ukrainian, and English; Zscaler also noted observed Covenant Grunt samples abusing the Filen cloud storage API for C2 communication. Additional timeline content references GRUNT in connection with APT28’s 2025 Operation Phantom Net Voxel alongside BEARDSHELL and SLIMAGENT. High-confidence capabilities directly supported by the content are that Grunt functions as a Covenant C2 implant used for post-exploitation and command-and-control within broader intrusion chains.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
WIZARD SPIDER

Notably, in the period following FIN12's hiatus in 2020, the group experimented with the use of other post-exploitation tools including Covenant (GRUNT), GRIMAGENT, and ANCHOR.

via web archiveweb.archive.org
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1059.001PowerShellEvidence1

This Custom Script Extension will download our Powershell Launcher and start the Grunt... For demonstration purposes, we’ll also repeat this process using the Run Command feature by sending a PowerShell command which will execute our Launch and run another Grunt.

Persistence

1 technique
T1543.003Windows ServiceEvidence1

For example we could: ... Install a service to launch ensure a Grunt is started if the VM is restarted.

Privilege Escalation

1 technique
T1543.003Windows ServiceEvidence1

For example we could: ... Install a service to launch ensure a Grunt is started if the VM is restarted.

Command and Control

2 techniques
T1105Ingress Tool TransferEvidence2

The Custom Script Extension ... downloads a script from a user-specified location (e.g. URL, blob storage, etc.) and then executes the script on a running Azure Windows or Linux VM.

T1219Remote Access ToolsEvidence1

We’ll set up a Covenant command and control (C2) server outside of the target Azure environment... This will connect back to the C2 server, and allow us to run commands as LocalSystem on the VM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.