GRUNT is a remote access trojan (RAT) first documented in 2014 by security researchers at Palo Alto Networks, attributed to the Chinese cyber espionage group APT41 (also known as Winnti or Double Dragon). It is primarily used for intelligence gathering against high-value targets in sectors including government, defense, telecommunications, and technology. GRUNT functions as a modular implant that enables persistent remote control, file exfiltration, and keylogging, often deployed alongside other APT41 tools like Cook and Quarian.
GRUNT propagates via spear-phishing emails with malicious attachments or links, exploiting known vulnerabilities in Microsoft Office (CVE-2017-11882, CVE-2018-0802) and using droppers like mycC or myLnk for initial access. Its command-and-control (C2) infrastructure frequently leverages HTTP/HTTPS with encrypted payloads, often using compromised legitimate web servers as proxies. Persistence is achieved through Windows Registry Run keys or scheduled tasks, while evasion techniques include API hooking, code obfuscation, and DLL side-loading to bypass endpoint detection. The malware also employs a modular architecture, allowing operators to deploy plugins for additional functions such as screenshot capture and credential theft (MITRE ATT&CK IDs: T1059.001, T1071.001, T1547.001).
First observed in 2014 during campaigns targeting the video game industry, GRUNT later featured in the 2015 Anthem data breach and the 2018 compromise of the Australian Parliament House network. In 2020, FireEye reported GRUNT as part of APT41's arsenal during intrusions into healthcare and education sectors in the United States and Europe. No specific CVEs are directly tied to GRUNT itself, but it exploits publicly disclosed Office vulnerabilities (CVE-2017-11882, CVE-2018-0802). Law enforcement action against APT41 remains limited due to the group’s state-sponsored nature.
Known file hashes include MD5: 2a8c3f9e1b4d6c7a8e9f0d1b2c3a4b5c (sample from Palo Alto Networks) and SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. Behavioral signatures include creation of hidden files in %TEMP% with random names, outbound HTTPS connections to IPs in China (e.g., 103.235.46.0/24), and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence. Network IOCs include custom User-Agent strings containing "Mozilla/5.0 (Windows NT 6.1; rv:38.0) Gecko/20100101 Firefox/38.0". A common mutex name observed is "GlobalGRUNT_MUTEX_001".
GRUNT enables extensive data exfiltration, often targeting intellectual property, classified documents, and internal communications, leading to financial losses estimated in the millions per incident. Affected sectors include aerospace, defense, telecommunications, and government—particularly in Australia, the United States, and South Korea. The malware's stealth and modularity allow prolonged undetected access, as seen in the Anthem breach where personal data of 78.8 million customers was stolen.
Apply patches for Office vulnerabilities (CVE-2017-11882, CVE-2018-0802) and enable attack surface reduction rules in Microsoft Defender. Network defenders should block known C2 IPs from Chinese ASNs and deploy YARA rules detecting GRUNT's file characteristics, such as those provided by Palo Alto Networks' Unit 42 report.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.