Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareRansomwareUsed by 5 actorsExploits 1 CVE

Covenant

Covenant is an open-source .NET post-exploitation and command-and-control framework first released in February 2019. It is used to establish C2 over HTTP and can use SSL/TLS to encrypt traffic. The framework supports PowerShell-based launchers for Grunt installation, WMI-based installation of new Grunt listeners through XSL files or command one-liners, and in-memory execution of .NET payloads. Reported Grunt capabilities in the provided content include .NET assembly loading, PowerShell execution, output streaming, and encrypted result uploads.

The content links Covenant to both general offensive-security use and multiple real-world malicious operations. It was identified as C2 infrastructure in broader criminal ecosystems, including a server at 62.233.50[.]25 associated with LockBit 3.0 affiliate infrastructure; Shodan and Censys reportedly labeled related Covenant infrastructure on port 7443, with SSL issuer and subject fields containing default values of "Covenant." VirusTotal artifacts tied to that IP included PowerShell scripts and executable payloads labeled as Covenant.

The strongest operational association in the content is with Sednit/APT28/Fancy Bear/Forest Blizzard, a Russian state-sponsored group linked to GRU Unit 26165. ESET reported that from April 2024 onward Sednit reworked Covenant into a primary long-term espionage implant and deployed it together with BeardShell for resilience. Sednit modified Covenant’s execution flow, replaced random implant naming with deterministic identifiers derived from machine characteristics, and added cloud-based communication protocols via the C2Bridge framework. Reported cloud C2 providers used by Sednit’s modified Covenant were pCloud in 2023, Koofr in 2024 and 2025, and Filen from July 2025. ESET observed some monitored machines remaining under surveillance for more than six months. Sednit used Covenant and BeardShell against Ukrainian military personnel, drone manufacturers, and organizations involved in drone research and development, as well as logistics and transportation companies outside Ukraine.

Multiple reports in the content describe APT28 campaigns in 2025 and 2026 using modified Covenant implants delivered through spearphishing. In one infection chain exploiting CVE-2026-21509 in Microsoft Office, malicious documents triggered WebDAV retrieval of payloads, leading to COM hijacking, a scheduled task named OneDriveHealth, deployment of EhStoreShell.dll and SplashScreen.png, extraction of shellcode hidden in PNG files, and in-memory launch of a modified Covenant implant referred to as CovenantGrunt or PrismexStager. This implant used filen.io as command-and-control infrastructure over HTTPS and reportedly implemented components named FilenApi, FilenMessenger, FilenEncryptor, and GruntExecutor, with a handshake using a 2048-bit RSA key pair and an AES-256 session key. Associated post-exploitation activity included reconnaissance with arp.exe, systeminfo.exe, and tracert.exe, process injection into svchost.exe, and preparation for lateral movement.

The content also states that modified Covenant variants used steganography by embedding shellcode in PNG files and extracting it at runtime, and that both BeardShell and Covenant extracted C2 addresses from images stored in cloud services. In Operation Phantom Net Voxel and related reporting, Covenant was described as using Filen, pCloud, and Koofr for C2, with HTTPS and additional ChaCha20-Poly1305 encryption layered on top of TLS in the broader campaign. Reported persistence and delivery mechanisms around these campaigns included spearphishing with weaponized Office documents, VBA macros in some cases, PowerShell execution, Registry Run Keys, COM hijacking, and scheduled-task abuse.

High-confidence indicators directly mentioned in the content include 62.233.50[.]25 as a Covenant C2 server; port 7443 with default SSL subject/issuer values of "Covenant" on related infrastructure; the January 2026 infection artifacts EhStoreShell.dll and SplashScreen.png; the scheduled task OneDriveHealth; malicious delivery domains freefoodaid[.]com, wellnesscaremed[.]com, wellnessmedcare[.]org, and longsauce[.]com; associated IPs 159.253.120.2, 193.187.148.169, and 23.227.202.14; and use of Filen-related infrastructure including filen.io and related domains. Overall, the content portrays Covenant as a legitimate open-source framework that has been repeatedly adapted by threat actors, especially APT28/Sednit, for stealthy, long-term espionage against Ukrainian and European military, government, transport, and defense-related targets.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2026-21509Microsoft Office Shell.Explorer.1 OLE Security Feature BypassExploited in the wild

In January 2026, Sednit also deployed Covenant in a series of spearphishing campaigns exploiting the CVE-2026-21509 vulnerability, as reported by CERT‑UA. | Across 2025 and 2026, Sednit repeatedly deployed BeardShell together with Covenant, a third major piece of its modern toolkit. Sednit heavily reworked this open-source implant to support long-term espionage and to implement a new network protocol based on yet another legitimate cloud provider.

via eset welivesecurity blogwelivesecurity.com
THREAT ACTORS

Groups observed using it

5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
hafnium

Covenant can establish command and control via HTTP.

via mitre attack websiteattack.mitre.org
APT28

Across 2025 and 2026, Sednit repeatedly deployed BeardShell together with Covenant, a third major piece of its modern toolkit. Sednit heavily reworked this open-source implant to support long-term espionage and to implement a new network protocol based on yet another legitimate cloud provider.

via eset welivesecurity blogwelivesecurity.com
Indrik Spider

"...execute payloads based on Donut and the Covenant post-exploitation framework."

via secureworks threat profilessecureworks.com
GRU Unit 26165

The attackers also customized the Covenant red-team framework to route encrypted command-and-control traffic through Koofr and Icedrive cloud services, making detection difficult.

via scworldscworld.com
APT29

In the recent attacks, the Russian threat group paired BeardShell with a heavily modified version of the open-source Covenant .NET post-exploitation framework.

via bleeping computerbleepingcomputer.com
MITRE ATT&CK

Techniques & procedures

30 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

2 techniques
T1583.006Web ServicesEvidence1

MITRE ATT&CK techniques ... T1583.006 Acquire Infrastructure: Web Services BeardShell relies on Icedrive cloud storage. Covenant relies on Filen cloud storage.

T1583.007ServerlessEvidence1

Instead of standard HTTP, APT28 built a custom bridge that uses the legitimate Koofr cloud service, with tasks and results travelling as encrypted files inside the operator's Koofr account.

Initial Access

2 techniques
T1566PhishingEvidence1

Spear phishing campaigns or the SedKit exploit kit delivered the Seduploader first stage.

T1566.001Spearphishing AttachmentEvidence1

електронних листів із вкладенням у вигляді DOC-файлу "BULLETEN_H.doc". Згаданий лист було відправлено на більше ніж 60 електронних адрес переважно центральних органів виконавчої влади України.

Execution

7 techniques
T1047Windows Management InstrumentationEvidence1

The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'

T1053.005Scheduled TaskEvidence2

...створення запланованої задачі "OneDriveHealth". Заплановане виконання задачі призведе до термінації та повторного запуску процесу explorer.exe...

T1059Command and Scripting InterpreterEvidence1

Silent Cartographer is simply an exercise in identifying the application in play (Covenant), researching any known exploits against it, retooling the published POC, executing the POC, and handling the incoming reverse shell.

T1059.001PowerShellEvidence2

The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."

T1059.003Windows Command ShellEvidence3

During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.

T1203Exploitation for Client ExecutionEvidence2

Відкриття документу за допомогою програми Microsoft Office призводить до встановлення мережевого з'єднання із зовнішнім ресурсом... DOC-файл "Consultation_Topics_Ukraine(Final).doc", що містив експлойт для ... CVE-2026-21509.

T1204.002Malicious FileEvidence1

подальшого завантаження файлу із заголовком файлу ярлика, який містить програмний код, призначений для завантаження та запуску виконуваного файлу.

Persistence

1 technique
T1053.005Scheduled TaskEvidence2

...створення запланованої задачі "OneDriveHealth". Заплановане виконання задачі призведе до термінації та повторного запуску процесу explorer.exe...

Privilege Escalation

2 techniques
T1053.005Scheduled TaskEvidence2

...створення запланованої задачі "OneDriveHealth". Заплановане виконання задачі призведе до термінації та повторного запуску процесу explorer.exe...

T1068Exploitation for Privilege EscalationEvidence1

If a user can fabricate a JWT by using the leaked JWT secret key, they can arbitrarily assign themselves admin-level credentials, log in, and wreak havoc on the server.

Stealth

2 techniques
T1027.003SteganographyEvidence3

Стеганография (T1027.003) прячет payload от файлового анализа: PNG с шеллкодом - не исполняемый файл...

T1620Reflective Code LoadingEvidence1

Background: Reflection # In .NET, reflection is the runtime feature that lets code discover and use types, methods, and load assemblies dynamically. Legitimate software uses it for plugins, dynamic loading, and tooling - but for attackers it is a defence evasion technique, similar to injection, but for managed code. They can load assemblies straight from bytes in memory, resolve method names on the fly, and execute payloads more discreetly.

Credential Access

1 technique
T1606.001Web CookiesEvidence1

Covenant versions prior to 0.5 all had the same JWT secret key in default builds. The JWT in Covenant is used to authenticate users to the Covenant web UI... If a user can fabricate a JWT by using the leaked JWT secret key, they can arbitrarily assign themselves admin-level credentials, log in, and wreak havoc on the server.

Discovery

1 technique
T1082System Information DiscoveryEvidence1

The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."

Collection

2 techniques
T1005Data from Local SystemEvidence1

MITRE ATT&CK techniques ... T1005 Data from Local System BeardShell, Covenant, and SlimAgent collect data from a compromised machine.

T1074Data StagedEvidence1

The infection chain stages a customised Covenant framework deployment in memory.

Command and Control

9 techniques
T1071Application Layer ProtocolEvidence6

In addition to being associated with Chang Way, 62.233.50[.]25 is also a Covenant Command and Control (C2) server.

T1071.001Web ProtocolsEvidence5

The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."

T1090.002External ProxyEvidence1

...в якості інфраструктури для управління COVENANT використовує легітимне хмарне сховище Filen (filen.io).

T1102Web ServiceEvidence1

BeardShell ... leverages the legitimate cloud storage service Icedrive as its C&C channel... Previously, in 2023, Sednit’s Covenant abused the legitimate cloud service pCloud, and in 2024–2025, Koofr ... Figure 11 shows the classes introduced by Sednit developers to communicate with the Filen cloud provider, used since July 2025.

T1102.002Bidirectional CommunicationEvidence1

Облачный C2 (Web Service, T1102.002) прячет сетевой трафик... Command and Control - Bidirectional Communication (T1102.002): BEARDSHELL работает через Icedrive API ... COVENANT - через Filen, pCloud, Koofr.

T1105Ingress Tool TransferEvidence4

The attackers then upgraded valuable targets to the X-Agent backdoor, often pairing it with the Sedreco loader and the X-Tunnel network pivot.

T1219Remote Access ToolsEvidence2

Cobalt Strike uses a command-line interface to interact with systems. Brute Ratel C4 can use cmd.exe for execution. Havoc can execute commands via cmd.exe. Covenant provides access to a Command Shell in Windows environments for follow-on command execution and tasking.

T1573Encrypted ChannelEvidence1

The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.

T1573.002Asymmetric CryptographyEvidence1

MITRE ATT&CK techniques ... T1573.002 Encrypted Channel: Asymmetric Cryptography BeardShell communications with Icedrive are encrypted using HTTPS. Covenant communications with its controller uses RSA-encrypted session keys.

Exfiltration

3 techniques
T1048Exfiltration Over Alternative ProtocolEvidence1

відкриття документу ... призводить до встановлення мережевого з'єднання із зовнішнім ресурсом з використанням протоколу WebDAV, подальшого завантаження файлу із заголовком файлу ярлика

T1567Exfiltration Over Web ServiceEvidence1

MITRE ATT&CK techniques ... T1567 Exfiltration Over Web Service BeardShell exfiltrates data to Icedrive. Covenant exfiltrates data to Filen.

T1567.002Exfiltration to Cloud StorageEvidence1

...эксфильтрация документов через тот же облачный канал (Exfiltration to Cloud Storage, T1567.002).

INDICATORS OF COMPROMISE

IOCs tracked for this family

66 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
28 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
24 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
14 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app8 days ago
domain●●●●●●●●●●●●View more in app8 days ago
domain●●●●●●●●●●●●View more in app8 days ago
domain●●●●●●●●●●●●View more in app8 days ago
domain●●●●●●●●●●●●View more in app14 days ago
domain●●●●●●●●●●●●View more in app14 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching66

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution5

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping30

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.