Covenant Grunt is the .NET implant used by the open-source Covenant command-and-control framework. It is generated from configurable implant templates and supports operational parameters including callback delay and jitter, connection-attempt limits, kill dates, certificate validation or pinning, SMB named-pipe communication settings, and selectable .NET runtime settings. Covenant can generate Grunt stagers and launchers through Windows execution mechanisms including WMIC, Regsvr32, Mshta, Cscript, and Wscript. Grunt has been used as post-compromise tooling by FIN12 and in espionage operations attributed to the Russian state-linked APT28 (Fancy Bear/Sednit) group. In 2026 APT28 activity targeting Central and Eastern European organizations used malicious Office documents exploiting CVE-2026-21509 to deploy PixyNetLoader, which could subsequently stage a Covenant Grunt implant. The observed targeting included Ukrainian public-sector recipients and users in Ukraine, Slovakia, and Romania. Covenant Grunt communications in that activity included abuse of cloud-storage APIs for command-and-control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2026-02-04 ⋅ StrikeReady ⋅ APT28’s Stealthy Multi-Stage Campaign Leveraging CVE‑2026‑21509 and Cloud C2 Infrastructure ... 2026-02-02 ⋅ Zscaler ⋅ APT28 Leverages CVE-2026-21509 in Operation Neusploit | 2026-03-10 ⋅ ESET Research ⋅ Sednit reloaded: Back in the trenches BEARDSHELL GRUNT SLIMAGENT X-Agent XTunnel
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2026-03-10 ⋅ ESET Research ⋅ Sednit reloaded: Back in the trenches BEARDSHELL GRUNT SLIMAGENT X-Agent XTunnel
Notably, in the period following FIN12's hiatus in 2020, the group experimented with the use of other post-exploitation tools including Covenant (GRUNT), GRIMAGENT, and ANCHOR.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
"GenerateWmicLauncher" and "GenerateWmicHostedLauncher" are present.
The code implements both `CscriptLauncher` and `WscriptLauncher`; their configuration includes `ScriptLanguage`, `LauncherString`, `StagerCode`, and `DiskCode`.
Task handling recognizes the "powershell", "powershellimport", and "powershellremotinggrunt" tasks; it can prepend imported PowerShell content to task parameters and generate a PowerShell launcher.
"GenerateCscriptLauncher" and "GenerateCscriptHostedLauncher" are present.
The launcher section defines GetMSBuildLauncher, GenerateMSBuildLauncher, and GenerateMSBuildHostedLauncher operations.
"GenerateInstallUtilLauncher" and "GenerateInstallUtilHostedLauncher" are present.
The code defines GetRegsvr32Launcher, GenerateRegsvr32Launcher, and GenerateRegsvr32HostedLauncher, including DLL name and parameter fields. | The code implements `Regsvr32Launcher`, including fields for `ParameterString` and `DllName`, and generates a launcher through `GenerateRegsvr32Launcher()`.
Each generated Grunt is assigned a `Listener`, `Profile`, certificate-validation options, certificate pinning, connection-attempt settings, delay, and jitter configuration.
"CreateHttpListener", "StartListener", and "GetHttpListeners" methods manage HTTP listeners.
The code includes "CreateBridgeListener", "GetBridgeListeners", and "GetOutboundGrunt" service methods.
The code tests whether an implant template communication type is SMB and uses SMBPipeName to find, connect, parent, and disconnect Grunts.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/framework appearing repeatedly in APT28 reporting as part of multi-stage campaigns.
An implant (agent) associated with the Covenant C2 framework, used for post-exploitation command-and-control on compromised hosts.
APT28 Operation Phantom Net Voxel BEARDSHELL GRUNT SLIMAGENT
Covenant-associated .NET implant briefly used by FIN12 as an alternative post-exploitation tool before the group reverted primarily to BEACON.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.