Covenant
MITRE ATT&CK: S1155 View on attack.mitre.org
Aliases: Covenant
- First seen
- 2019-06-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- linux, macos, windows
- Last IoC activity
- 2026-07-21 19:24:56
- Profile updated
- 2026-07-07 12:59:35
Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace
Targeted regions: country_code:us country_code:cn
Context
Covenant is a multi-platform command and control framework written in .NET. While designed for penetration testing and security research, the tool has also been used by threat actors such as HAFNIUM during operations. Covenant functions through a central listener managing multiple deployed "Grunts" that communicate back to the controller.
Detection coverage
- 1 YARA rules
- 344 Sigma rules
Malware & tools used
- PowerShell (attack-pattern)
- Non-Standard Port (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Regsvr32 (attack-pattern)
- InstallUtil (attack-pattern)
- System Information Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Web Protocols (attack-pattern)
- Mshta (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
Used by threat actors
- HAFNIUM (threat-actor)
Detection rules
- DITEKSHEN_MALWARE_Win_Covenantgruntstager (yara-rule)
Reports & references
- Microsoft — Hafnium Targeting Exchange Servers (report)
- MITRE ATT&CK — S1155 (report)
- github.com — Covenant (report)