Grunt is an implant associated with the open-source Covenant command-and-control framework and has been observed as post-compromise tooling in multiple intrusion contexts. In reporting tied to APT28, also known as Fancy Bear or Sednit, a Covenant Grunt implant was deployed as a later-stage payload in a Windows-focused infection chain that began with malicious Microsoft Office documents exploiting CVE-2026-21509. In that activity, phishing emails targeting users in Central and Eastern Europe delivered weaponized RTF documents, which led to a dropper and then to additional payloads including PixyNetLoader and a Grunt implant. The campaign was assessed as Russian state-sponsored espionage activity targeting government-related users, including organizations in Ukraine and neighboring countries. Grunt samples in that cluster were also reported using cloud-storage-backed communications for command and control.
Grunt has also appeared in financially motivated intrusions attributed to FIN12, where it was used intermittently alongside other post-exploitation frameworks such as Cobalt Strike Beacon, Meterpreter, Anchor, and GRIMAGENT during ransomware operations. In that context, Grunt functioned as an operator-controlled implant within broader hands-on-keyboard activity after initial access had already been obtained by partner access brokers or malware delivery chains.
Because Grunt is a Covenant framework implant rather than a standalone malware family with a unique criminal ecosystem, its observed role is best characterized as a backdoor used for post-exploitation. High-confidence reporting supports its use on Windows systems for remote operator access, follow-on payload staging, and broader intrusion enablement in both espionage and ransomware-related operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2026-02-04 ⋅ StrikeReady ⋅ APT28’s Stealthy Multi-Stage Campaign Leveraging CVE‑2026‑21509 and Cloud C2 Infrastructure ... 2026-02-02 ⋅ Zscaler ⋅ APT28 Leverages CVE-2026-21509 in Operation Neusploit | 2026-03-10 ⋅ ESET Research ⋅ Sednit reloaded: Back in the trenches BEARDSHELL GRUNT SLIMAGENT X-Agent XTunnel
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2026-03-10 ⋅ ESET Research ⋅ Sednit reloaded: Back in the trenches BEARDSHELL GRUNT SLIMAGENT X-Agent XTunnel
Notably, in the period following FIN12's hiatus in 2020, the group experimented with the use of other post-exploitation tools including Covenant (GRUNT), GRIMAGENT, and ANCHOR.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/framework appearing repeatedly in APT28 reporting as part of multi-stage campaigns.
An implant (agent) associated with the Covenant C2 framework, used for post-exploitation command-and-control on compromised hosts.
APT28 Operation Phantom Net Voxel BEARDSHELL GRUNT SLIMAGENT
Covenant-associated .NET implant briefly used by FIN12 as an alternative post-exploitation tool before the group reverted primarily to BEACON.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.