Skip to content

Grunt

Grunt is an implant associated with the open-source Covenant command-and-control framework and has been observed as post-compromise tooling in multiple intrusion contexts.

Profile source: Mallory opens in a new tab

Grunt

Family profile

Grunt is an implant associated with the open-source Covenant command-and-control framework and has been observed as post-compromise tooling in multiple intrusion contexts. In reporting tied to APT28, also known as Fancy Bear or Sednit, a Covenant Grunt implant was deployed as a later-stage payload in a Windows-focused infection chain that began with malicious Microsoft Office documents exploiting CVE-2026-21509. In that activity, phishing emails targeting users in Central and Eastern Europe delivered weaponized RTF documents, which led to a dropper and then to additional payloads including PixyNetLoader and a Grunt implant. The campaign was assessed as Russian state-sponsored espionage activity targeting government-related users, including organizations in Ukraine and neighboring countries. Grunt samples in that cluster were also reported using cloud-storage-backed communications for command and control.

Grunt has also appeared in financially motivated intrusions attributed to FIN12, where it was used intermittently alongside other post-exploitation frameworks such as Cobalt Strike Beacon, Meterpreter, Anchor, and GRIMAGENT during ransomware operations. In that context, Grunt functioned as an operator-controlled implant within broader hands-on-keyboard activity after initial access had already been obtained by partner access brokers or malware delivery chains.

Because Grunt is a Covenant framework implant rather than a standalone malware family with a unique criminal ecosystem, its observed role is best characterized as a backdoor used for post-exploitation. High-confidence reporting supports its use on Windows systems for remote operator access, follow-on payload staging, and broader intrusion enablement in both espionage and ransomware-related operations.

Capabilities

  • Post Exploitation

Reported operators

Threat actors

2 named in public reporting
APT28

2026-03-10 ⋅ ESET Research ⋅ Sednit reloaded: Back in the trenches BEARDSHELL GRUNT SLIMAGENT X-Agent XTunnel

WIZARD SPIDER

Notably, in the period following FIN12's hiatus in 2020, the group experimented with the use of other post-exploitation tools including Covenant (GRUNT), GRIMAGENT, and ANCHOR.

Exploited software

Vulnerabilities linked to Grunt

1 CVEs

MITRE ATT&CK

Grunt in ATT&CK

5 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.