Covenant Grunt is a .NET implant associated with the open-source Covenant command-and-control framework. In the provided reporting, it appears as the final payload in APT28/Fancy Bear/UAC-0001 campaigns, especially Operation Neusploit and related PixyNetLoader activity. The implant is delivered through multi-stage infection chains initiated by weaponized Microsoft Office/RTF documents exploiting CVE-2026-21509, after which droppers such as PixyNetLoader and components such as EhStoreShell.dll extract shellcode or an embedded .NET assembly from steganographically modified PNG files and execute the Grunt payload directly in memory. The malware is described as providing full remote control over the victim system and long-term command-and-control access. In the cited samples, Covenant Grunt used the FILEN cloud service, including the Filen API as a C2 bridge, for communications and tasking. Reported tradecraft around its deployment includes COM hijacking persistence, DLL proxying, anti-sandbox timing checks, WebDAV-based retrieval in some chains, and PNG least-significant-bit steganography. The campaigns were attributed to APT28 and targeted Ukrainian government entities as well as European government, defense, transportation, diplomatic, maritime, and military-related organizations. High-confidence indicators mentioned in the content include use of companion PNG files such as %programdata%\Microsoft OneDrive\setup\Cache\SplashScreen.png, COM hijack paths under \Classes\CLSID{68DDBB56-9D1D-4FD9-89C5-C0DA2A625392}\InProcServer32\ and \Classes\CLSID{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\InProcServer32, and one reported embedded Filen parent folder UUID fe644d8c-2601-46ea-bf7d-3db110aa08d4.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Threat hunters have also charted the evolution of PixyNetLoader, a malware loader attributed to APT28 in connection with campaigns exploiting a Microsoft Office vulnerability (CVE-2026-21509), to extract a COVENANT Grunt implant.
CVE-2026-21513 zero-day: Exploited at least 11 days before the February 10, 2026 patch release... By combining zero-day exploitation (CVE-2026-21513) with rapid weaponization of newly disclosed vulnerabilities (CVE-2026-21509)... Immediate mitigations Patching: Prioritize the remediation of both CVE-2026-21509 and CVE-2026-21513 across the entire fleet immediately.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Threat hunters have also charted the evolution of PixyNetLoader, a malware loader attributed to APT28 in connection with campaigns exploiting a Microsoft Office vulnerability (CVE-2026-21509), to extract a COVENANT Grunt implant.
The exploitation delivers a multi-stage infection chain culminating in the NotDoor Outlook backdoor and Covenant Grunt implants.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
"The shellcode employs CLR hosting to load and execute an embedded .NET assembly in-memory: a Covenant Grunt implant..."
The main purpose of this 64-bit shellcode is to load a .NET assembly embedded inside it. In order to load a managed assembly from native code, the shellcode uses the CLR hosting technique.
CVE-2026-21509, a remote code execution vulnerability in Microsoft Office affecting RTF and OLE document processing... weaponized the flaw in malicious RTF files targeting Ukrainian government agencies and European defense, transportation, and diplomatic entities.
The entire chain is designed for resilience and evasion, utilizing encrypted payloads, legitimate cloud services for C2, in-memory execution, and process injection to minimize forensic artifacts
The entire chain is designed for resilience and evasion, utilizing encrypted payloads... Zscaler said... similar techniques, including... XOR string encryption techniques...
PixyNetLoader loads the .PNG file, extracts a Covenant Grunt payload from the pixels’ LSBs... The payload is contained in the least significant bits of the file’s pixels.
The Grunt payload uses the FILEN cloud service as its command-and-control channel.
The payload remains a Covenant Grunt malware (VersionInfo Publish.exe ) using FILEN as Cloud C2
“the implant uses the Filen API as a C2Bridge to communicate and receive tasks from the threat actor. This abuse of legitimate APIs…”
“Abused Filen API as a C2 bridge between the implant and actor-controlled Covenant listener.”
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An in-memory payload extracted by PixyNetLoader from steganographically embedded PNG data and used for command-and-control communications via the FILEN cloud service.
An implant delivered by PixyNetLoader in APT28 campaigns exploiting a Microsoft Office vulnerability.
The in-memory payload delivered by PixyNetLoader; a Covenant Grunt implant used as the final backdoor payload and communicating through FILEN cloud C2.
An implant delivered in the final stage of the observed exploitation chain following weaponized Office document attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.