Skip to content

Grunt

Covenant Grunt is the .NET implant used by the open-source Covenant command-and-control framework.

Profile source: Mallory opens in a new tab

Grunt

Family profile

Covenant Grunt is the .NET implant used by the open-source Covenant command-and-control framework. It is generated from configurable implant templates and supports operational parameters including callback delay and jitter, connection-attempt limits, kill dates, certificate validation or pinning, SMB named-pipe communication settings, and selectable .NET runtime settings. Covenant can generate Grunt stagers and launchers through Windows execution mechanisms including WMIC, Regsvr32, Mshta, Cscript, and Wscript. Grunt has been used as post-compromise tooling by FIN12 and in espionage operations attributed to the Russian state-linked APT28 (Fancy Bear/Sednit) group. In 2026 APT28 activity targeting Central and Eastern European organizations used malicious Office documents exploiting CVE-2026-21509 to deploy PixyNetLoader, which could subsequently stage a Covenant Grunt implant. The observed targeting included Ukrainian public-sector recipients and users in Ukraine, Slovakia, and Romania. Covenant Grunt communications in that activity included abuse of cloud-storage APIs for command-and-control.

Capabilities

  • Post Exploitation

Reported operators

Threat actors

2 named in public reporting
APT28

2026-03-10 ⋅ ESET Research ⋅ Sednit reloaded: Back in the trenches BEARDSHELL GRUNT SLIMAGENT X-Agent XTunnel

fin12

Notably, in the period following FIN12's hiatus in 2020, the group experimented with the use of other post-exploitation tools including Covenant (GRUNT), GRIMAGENT, and ANCHOR.

Exploited software

Vulnerabilities linked to Grunt

1 CVEs

MITRE ATT&CK

Grunt in ATT&CK

24 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.