2026-03-10 ⋅ ESET Research ⋅ Sednit reloaded: Back in the trenches BEARDSHELL GRUNT SLIMAGENT X-Agent XTunnel
Grunt
Grunt is an implant associated with the open-source Covenant command-and-control framework and has been observed as post-compromise tooling in multiple intrusion contexts.
Profile source: Mallory opens in a new tabGrunt
Family profile
Grunt is an implant associated with the open-source Covenant command-and-control framework and has been observed as post-compromise tooling in multiple intrusion contexts. In reporting tied to APT28, also known as Fancy Bear or Sednit, a Covenant Grunt implant was deployed as a later-stage payload in a Windows-focused infection chain that began with malicious Microsoft Office documents exploiting CVE-2026-21509. In that activity, phishing emails targeting users in Central and Eastern Europe delivered weaponized RTF documents, which led to a dropper and then to additional payloads including PixyNetLoader and a Grunt implant. The campaign was assessed as Russian state-sponsored espionage activity targeting government-related users, including organizations in Ukraine and neighboring countries. Grunt samples in that cluster were also reported using cloud-storage-backed communications for command and control.
Grunt has also appeared in financially motivated intrusions attributed to FIN12, where it was used intermittently alongside other post-exploitation frameworks such as Cobalt Strike Beacon, Meterpreter, Anchor, and GRIMAGENT during ransomware operations. In that context, Grunt functioned as an operator-controlled implant within broader hands-on-keyboard activity after initial access had already been obtained by partner access brokers or malware delivery chains.
Because Grunt is a Covenant framework implant rather than a standalone malware family with a unique criminal ecosystem, its observed role is best characterized as a backdoor used for post-exploitation. High-confidence reporting supports its use on Windows systems for remote operator access, follow-on payload staging, and broader intrusion enablement in both espionage and ransomware-related operations.
Capabilities
- Post Exploitation
Reported operators
Threat actors
2 named in public reportingNotably, in the period following FIN12's hiatus in 2020, the group experimented with the use of other post-exploitation tools including Covenant (GRUNT), GRIMAGENT, and ANCHOR.
Exploited software
Vulnerabilities linked to Grunt
1 CVEsMITRE ATT&CK