Grunt
Grunt is an implant associated with the open source Covenant command-and-control framework. The provided content places it in post-exploitation and espionage contexts rather than as a standalone malware family with uniquely described functionality. Mandiant reported that FIN12 intermittently used GRUNT during 2020 as one of several post-exploitation tools alongside Cobalt Strike BEACON, METERPRETER, ANCHOR, and GRIMAGENT after the group’s 2020 hiatus. In separate reporting on Russia-linked APT28/Fancy Bear activity, Zscaler observed a 2026 phishing campaign exploiting CVE-2026-21509, a Microsoft Office/Microsoft 365 vulnerability that bypasses OLE mitigations via malicious RTF documents. In one observed infection chain, exploitation led to download of a malicious dropper DLL, then a previously undocumented loader named PixyNetLoader, which staged additional payloads including a Covenant Grunt implant. That campaign targeted users in Central and Eastern Europe, including Ukraine, Slovakia, and Romania, with lures in Romanian, Ukrainian, and English; Zscaler also noted observed Covenant Grunt samples abusing the Filen cloud storage API for C2 communication. Additional timeline content references GRUNT in connection with APT28’s 2025 Operation Phantom Net Voxel alongside BEARDSHELL and SLIMAGENT. High-confidence capabilities directly supported by the content are that Grunt functions as a Covenant C2 implant used for post-exploitation and command-and-control within broader intrusion chains.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Notably, in the period following FIN12's hiatus in 2020, the group experimented with the use of other post-exploitation tools including Covenant (GRUNT), GRIMAGENT, and ANCHOR.
Techniques & procedures
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
1 technique
Execution
Persistence
1 technique
Persistence
Privilege Escalation
1 technique
Privilege Escalation
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An implant (agent) associated with the Covenant C2 framework, used for post-exploitation command-and-control on compromised hosts.
APT28 Operation Phantom Net Voxel BEARDSHELL GRUNT SLIMAGENT
Covenant-associated .NET implant briefly used by FIN12 as an alternative post-exploitation tool before the group reverted primarily to BEACON.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.