Covenant is an open-source C#/.NET command-and-control and post-exploitation framework first released in February 2019. Designed for security testing and red-team operations, it has also been used in malicious intrusions. Its implant agents, called Grunts, provide remote task execution on Windows systems through dynamically compiled .NET code and encrypted command-and-control communications. The framework supports HTTP-based communications and SMB-linked child implants for network pivoting.
Covenant supports command-shell and PowerShell execution, arbitrary C# task compilation, credential collection, file retrieval, screenshot capture, token impersonation, UAC bypass, and lateral movement through WMI, DCOM, and PowerShell remoting. Many functions use SharpSploit. Persistence mechanisms include Registry Run keys and WMI event subscriptions. Its launchers support binary, shellcode, PowerShell, MSBuild, InstallUtil, WMIC, Regsvr32, Mshta, Cscript, and Wscript execution formats. These options enable deployment through legitimate Windows utilities and in-memory execution, reducing reliance on conventional executable payloads.
Hafnium, also tracked as Ant, deployed Covenant after compromising Microsoft Exchange servers during the 2021 exploitation campaigns. Sednit, also known as APT28, Fancy Bear, and Forest Blizzard, substantially modified Covenant for long-term espionage, including deterministic implant identifiers and cloud-based command-and-control through pCloud, Koofr, and Filen. These variants have been deployed alongside BeardShell against Ukrainian governmental and military targets. A Covenant Grunt stager also forms part of the PRISMEX toolkit used against Ukrainian defense operations and military, humanitarian, and logistics support infrastructure across Central and Eastern Europe. Observed delivery chains include spearphishing with weaponized Office documents, exploitation of CVE-2026-21509, and loader-mediated deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft also reported that Ant deployed post-compromise tools such as Covenant, PowerCat, and Nishang.
Microsoft also reported that Ant deployed post-compromise tools such as Covenant, PowerCat, and Nishang.
Spoločnosť Microsoft vydala mimoriadne bezpečnostné aktualizácie kancelárskeho balíka Microsoft Office, ktoré opravujú aktívne zneužívanú zero-day zraniteľnosť. CVE-2026-21509 možno zneužiť podvrhnutím špeciálne vytvorených súborov na obídenie bezpečnostných mechanizmov pre ochranu pred zneužitím niektorých funkcií COM/OLE a získanie úplnej kontroly nad systémom. | Cieľom je nainštalovať malvér MiniDoor (kradne e-maily) a PixyNetLoader, ktorý nainštaluje útočný nástroj Covenant.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The suite consists of three components: a dropper, a loader, and a staging tool based on the open-source Covenant framework.
Microsoft also reported that Ant deployed post-compromise tools such as Covenant, PowerCat, and Nishang.
Microsoft also reported that Ant deployed post-compromise tools such as Covenant, PowerCat, and Nishang.
"...execute payloads based on Donut and the Covenant post-exploitation framework."
The attackers also customized the Covenant red-team framework to route encrypted command-and-control traffic through Koofr and Icedrive cloud services, making detection difficult.
In the recent attacks, the Russian threat group paired BeardShell with a heavily modified version of the open-source Covenant .NET post-exploitation framework.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
The unauthenticated CovenantHub SignalR hub allows callers to invoke CreateHttpListener and receive a signed JWT token, which can then authenticate against the entire operator API.
Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener.
Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can use the obtained token to authenticate against the entire operator API and access grunts, credentials, binaries, events, and the operator roster.
"GenerateWmicLauncher" and "GenerateWmicHostedLauncher" are present.
The code implements both `CscriptLauncher` and `WscriptLauncher`; their configuration includes `ScriptLanguage`, `LauncherString`, `StagerCode`, and `DiskCode`.
The launcher service exposes `GetPowerShellLauncher`, `GeneratePowerShellLauncher`, and `GeneratePowerShellHostedLauncher`; the commit description also references `PowerShellRemot...` launcher commands. | Task handling recognizes the "powershell", "powershellimport", and "powershellremotinggrunt" tasks; it can prepend imported PowerShell content to task parameters and generate a PowerShell launcher.
"GenerateCscriptLauncher" and "GenerateCscriptHostedLauncher" are present.
"GenerateWscriptLauncher" and "GenerateWscriptHostedLauncher" are present.
The unauthenticated CovenantHub SignalR hub allows callers to invoke CreateHttpListener and receive a signed JWT token, which can then authenticate against the entire operator API.
Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener.
CreateHttpListener mints a brand new backing CovenantUser, assigns it the Listener role, generates a JWT signed with the server signing key, and returns that JWT to the caller.
CreateProcessWithLogonW ... provides a native way to spawn a new process with different network-only credentials ... the built in Windows utility, runas, is a simple wrapper around CreateProcessWithLogonW and the /NETONLY flag provides a native way to spawn a new process with different network-only credentials.
The unauthenticated CovenantHub SignalR hub allows callers to invoke CreateHttpListener and receive a signed JWT token, which can then authenticate against the entire operator API.
Access Token Manipulation (ATT&CK technique: T1134) ... this section will explain how attackers can abuse access tokens and target the fundamental trust relationships in Windows domains to compromise entire networks.
CreateProcessWithLogonW ... provides a native way to spawn a new process with different network-only credentials ... the built in Windows utility, runas, is a simple wrapper around CreateProcessWithLogonW and the /NETONLY flag provides a native way to spawn a new process with different network-only credentials.
The code contains a "bypassuacgrunt" task that resolves a launcher executable and appends the launcher arguments and execution directory required for the BypassUAC task. | The cited latest commit is titled `Fix launcher commands (i.e. BypassUacGrunt, WMIGrunt, PowerShellRemot...)`.
`CompileGruntCode` compiles substituted C# implant-template source through `Compiler.Compile`, including .NET Framework and .NET Core compilation requests.
The unauthenticated CovenantHub SignalR hub allows callers to invoke CreateHttpListener and receive a signed JWT token, which can then authenticate against the entire operator API.
The launcher section defines GetMSBuildLauncher, GenerateMSBuildLauncher, and GenerateMSBuildHostedLauncher operations.
Access Token Manipulation (ATT&CK technique: T1134) ... this section will explain how attackers can abuse access tokens and target the fundamental trust relationships in Windows domains to compromise entire networks.
"GenerateInstallUtilLauncher" and "GenerateInstallUtilHostedLauncher" are present.
The launcher service exposes `GetRegsvr32Launcher`, `GenerateRegsvr32Launcher`, and `GenerateRegsvr32HostedLauncher`. | The code defines GetRegsvr32Launcher, GenerateRegsvr32Launcher, and GenerateRegsvr32HostedLauncher, including DLL name and parameter fields. | The code implements `Regsvr32Launcher`, including fields for `ParameterString` and `DllName`, and generates a launcher through `GenerateRegsvr32Launcher()`.
Each generated Grunt is assigned a `Listener`, `Profile`, certificate-validation options, certificate pinning, connection-attempt settings, delay, and jitter configuration.
"CreateHttpListener", "StartListener", and "GetHttpListeners" methods manage HTTP listeners.
For `CommunicationType.SMB`, the generated template replaces read/write formats and `{{REPLACE_PIPE_NAME}}` with the configured SMB pipe name.
The code includes "CreateBridgeListener", "GetBridgeListeners", and "GetOutboundGrunt" service methods.
The code tests whether an implant template communication type is SMB and uses SMBPipeName to find, connect, parent, and disconnect Grunts.
Hosted-file functionality invokes listener.HostFile(file), while multiple launcher types implement Generate*HostedLauncher using a HostedFile and listener. | `ILauncherService` exposes `GenerateBinaryHostedLauncher`, `GenerateShellCodeHostedLauncher`, `GeneratePowerShellHostedLauncher`, and equivalent hosted launchers for several execution methods.
99 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
71 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source .NET C2 framework whose Grunt implant/stager is used as the final PRISMEX payload for command-and-control and task execution.
Modified implant/loader used to embed shellcode into PNG files for steganographic delivery, extract it at runtime, recover C2 information from cloud-hosted images, and communicate through Filen, pCloud, and Koofr.
A customized in-memory deployment of the Covenant framework used in Operation Phantom Net Voxel as part of APT28's modern implant chain.
An implant used by Sednit against Ukrainian military personnel and drone-related organizations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.