Covenant

MITRE ATT&CK: S1155 View on attack.mitre.org

Aliases: Covenant

First seen
2019-06-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
linux, macos, windows
Last IoC activity
2026-07-21 19:24:56
Profile updated
2026-07-07 12:59:35

Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace

Targeted regions: country_code:us country_code:cn

Context

Covenant is a multi-platform command and control framework written in .NET. While designed for penetration testing and security research, the tool has also been used by threat actors such as HAFNIUM during operations. Covenant functions through a central listener managing multiple deployed "Grunts" that communicate back to the controller.

Detection coverage

  • 1 YARA rules
  • 344 Sigma rules

Malware & tools used

  • PowerShell (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Regsvr32 (attack-pattern)
  • InstallUtil (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Web Protocols (attack-pattern)
  • Mshta (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)

Used by threat actors

Detection rules

  • DITEKSHEN_MALWARE_Win_Covenantgruntstager (yara-rule)

Reports & references

  • Microsoft — Hafnium Targeting Exchange Servers (report)
  • MITRE ATT&CK — S1155 (report)
  • github.com — Covenant (report)

External references