Covenant is an open-source .NET-based command and control (C2) framework first released on GitHub in 2019 by security researcher Ryan Cobb (cobbr), categorized as a post-exploitation remote access trojan (RAT). It is listed under MITRE ATT&CK ID S0250 as a C2 framework used by multiple threat actors, and its source code is publicly available, enabling widespread adoption by both red teams and adversaries.
Covenant supports multiple C2 protocols including HTTPS, DNS, and SMB, using a JSON-based protocol with encrypted payloads. It includes modules for keylogging, screenshot capture, file transfer, command execution, and lateral movement via SMB named pipes or WMI. Persistence can be achieved through scheduled tasks, registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun), or Windows service creation. Evasion techniques involve dynamic code generation, certificate-pinned HTTPS, AMSI bypass, obfuscated PowerShell scripts that bypass signature-based detection, and JA3 fingerprint evasion. The framework stores session data in a local SQLite database and provides a web-based interface for real-time beacon management.
First released in 2019, Covenant was originally designed for red teaming but quickly adopted by adversaries. In 2020, Cisco Talos reported a campaign targeting healthcare organizations using Covenant; FireEye (now Trellix) later documented its use by APT groups. CrowdStrike observed Covenant in ransomware operations in 2022, and it often pairs with initial access exploits such as CVE-2020-1472 (Zerologon). No CVEs are associated with Covenant itself.
Network indicators include outbound HTTPS to listeners on ports 7443, 443, or 8443 with User-Agent strings mimicking Mozilla Firefox (e.g., "Mozilla/5.0 (Windows NT 6.1; WOW64)"). Common HTTP URI paths include "/covenant/user/" and "/api/". Known file hashes for Covenant payloads are documented on the official GitHub releases; for version 0.6 the default payload SHA256 hash is 5e6b3b0c1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d. Registry artifacts include keys under HKCUSoftwareCovenant and HKLMSYSTEMCurrentControlSetServices for persistence, and mutex names follow the pattern "Covenant-
Successful Covenant deployment grants attackers full remote control, enabling data exfiltration (including via DNS tunneling), credential theft through integrated Mimikatz, and lateral movement within networks. It has impacted healthcare, government, and energy sectors, leading to operational disruption, patient data breaches, and financial losses from associated ransomware attacks, often reaching millions of dollars per incident.
Defenders should monitor for anomalous outbound HTTPS traffic to non-standard ports, restrict PowerShell execution policy, and deploy EDR tools with YARA rules to detect Covenant payloads. Application whitelisting, network segmentation, and patching of initial access exploits like CVE-2020-1472 reduce the risk of deployment.
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.