2026-03-10 ⋅ ESET Research ⋅ Sednit reloaded: Back in the trenches BEARDSHELL GRUNT SLIMAGENT X-Agent XTunnel
Grunt
Covenant Grunt is the .NET implant used by the open-source Covenant command-and-control framework.
Profile source: Mallory opens in a new tabGrunt
Family profile
Covenant Grunt is the .NET implant used by the open-source Covenant command-and-control framework. It is generated from configurable implant templates and supports operational parameters including callback delay and jitter, connection-attempt limits, kill dates, certificate validation or pinning, SMB named-pipe communication settings, and selectable .NET runtime settings. Covenant can generate Grunt stagers and launchers through Windows execution mechanisms including WMIC, Regsvr32, Mshta, Cscript, and Wscript. Grunt has been used as post-compromise tooling by FIN12 and in espionage operations attributed to the Russian state-linked APT28 (Fancy Bear/Sednit) group. In 2026 APT28 activity targeting Central and Eastern European organizations used malicious Office documents exploiting CVE-2026-21509 to deploy PixyNetLoader, which could subsequently stage a Covenant Grunt implant. The observed targeting included Ukrainian public-sector recipients and users in Ukraine, Slovakia, and Romania. Covenant Grunt communications in that activity included abuse of cloud-storage APIs for command-and-control.
Capabilities
- Post Exploitation
Reported operators
Threat actors
2 named in public reportingNotably, in the period following FIN12's hiatus in 2020, the group experimented with the use of other post-exploitation tools including Covenant (GRUNT), GRIMAGENT, and ANCHOR.
Exploited software
Vulnerabilities linked to Grunt
1 CVEsMITRE ATT&CK