GRUNT

Aliases: Covenant

First seen
2019-04-01 00:00:00
Malware type
rat
Family
Malware family
Last IoC activity
2026-05-31 10:00:24
Profile updated
2026-07-07 14:45:53

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:cn country_code:ru

Context

GRUNT, also known as Covenant, is a post-exploitation command and control tool primarily used in red team operations. It is capable of executing arbitrary commands on a targeted system and supports a wide range of attack functionalities.

Detection coverage

  • 1 YARA rules

Exploited vulnerabilities

  • CVE-2026-21509 (vulnerability)

Detection rules

  • DITEKSHEN_MALWARE_Win_Covenantgruntstager (yara-rule)

Reports & references

  • jsac.jpcert.or.jp — Jsac2024 1 9 Takeda Furukawa En (report)
  • blog.sekoia.io — Apt28 Operation Phantom Net Voxel (report)
  • ESET — Sednit Reloaded Back Trenches (report)
  • CERT-UA — 6284080 (report)
  • michaelkoczwara.medium.com — Hunting C2 With Shodan 223Ca250D06F (report)
  • Cisco Talos — Building Bypass With Msbuild (report)
  • strikeready.com — Apt28S Campaign Leveraging Cve%E2%80%912026%E2%80%9121509 And Cloud C2 Infrastructure (report)
  • trellix.com — Apt28 Stealthy Campaign Leveraging Cve 2026 21509 Cloud C2 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Grunt (report)
  • twitter.com — 1208141697282117633 (report)
  • telsy.com — 5776 (report)
  • ti.qianxin.com — Suspected Russian Speaking Attackers Use Covid19 Vaccine Decoys Against Middle East (report)
  • CERT-UA — 6287250 (report)

External references