GRUNT
Aliases: Covenant
- First seen
- 2019-04-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-05-31 10:00:24
- Profile updated
- 2026-07-07 14:45:53
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:cn country_code:ru
Context
GRUNT, also known as Covenant, is a post-exploitation command and control tool primarily used in red team operations. It is capable of executing arbitrary commands on a targeted system and supports a wide range of attack functionalities.
Detection coverage
- 1 YARA rules
Exploited vulnerabilities
- CVE-2026-21509 (vulnerability)
Detection rules
- DITEKSHEN_MALWARE_Win_Covenantgruntstager (yara-rule)
Reports & references
- jsac.jpcert.or.jp — Jsac2024 1 9 Takeda Furukawa En (report)
- blog.sekoia.io — Apt28 Operation Phantom Net Voxel (report)
- ESET — Sednit Reloaded Back Trenches (report)
- CERT-UA — 6284080 (report)
- michaelkoczwara.medium.com — Hunting C2 With Shodan 223Ca250D06F (report)
- Cisco Talos — Building Bypass With Msbuild (report)
- strikeready.com — Apt28S Campaign Leveraging Cve%E2%80%912026%E2%80%9121509 And Cloud C2 Infrastructure (report)
- trellix.com — Apt28 Stealthy Campaign Leveraging Cve 2026 21509 Cloud C2 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Grunt (report)
- twitter.com — 1208141697282117633 (report)
- telsy.com — 5776 (report)
- ti.qianxin.com — Suspected Russian Speaking Attackers Use Covid19 Vaccine Decoys Against Middle East (report)
- CERT-UA — 6287250 (report)