Pony, also widely known as Fareit, is a Windows credential-stealing malware family used in financially motivated intrusion and malware-delivery operations. It is designed to harvest credentials and other sensitive data from infected systems, and has been observed stealing browser-stored credentials and related account information. Pony has also been used as a secondary payload and as part of broader criminal infection chains in which it enables follow-on malware deployment.
Pony has commonly been delivered through phishing and spearphishing campaigns using malicious attachments, including executable archives and weaponized documents. Document-based delivery has included Microsoft Office files exploiting CVE-2017-11882 as well as macro-enabled Word documents. Campaigns have used social-engineering lures such as invoices, payment notices, and signature-related messages, and some samples have been disguised to appear trustworthy, including use of familiar document or application icons. Pony has also appeared in infections delivered by other malware families and loaders, including Hancitor, and in multi-stage chains involving Vawtrak and Nymaim.
The malware has been associated with commodity cybercrime ecosystems and malware-as-a-service usage. Reporting has linked its use to spam operations, botnet-driven distribution, and historical use by actors connected to Carbanak-era criminal activity. Pony has also been referenced alongside large-scale exploit-kit and phishing distribution activity, reflecting its role as a broadly reused infostealer rather than an actor-exclusive tool.
Operationally, Pony has exhibited defense-evasion behavior such as deleting itself after execution. It has been repeatedly observed in campaigns targeting Windows endpoints across enterprise and consumer environments, especially where email-borne malware delivery is effective. In addition to direct credential theft, Pony has frequently served as an enabling component in larger intrusion chains that culminate in banking malware, additional stealers, or other payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Trend Micro’s initial and ongoing analysis also found that a spammer group is also actively exploiting CVE-2017-11882 to infect systems with information stealers Pony/FAREIT and FormBook.
CVE-2015-0311 (Flash up to 16.0.0.287) integrating Exploit Kits Patched with Flash 16.0.0.296 ... first seen exploited by Angler EK ... soon after used in standalone mode in huge malvert campaign ... integrated today in RIG ... Fiesta ... Nuclear Pack ... Sweet Orange ... Neutrino ... Magnitude | ...Bedep (doing adfraud and grabbing malware : Pony mostly from what I saw)... CVE-2015-0311 used in standalone mode to drop Bedep grab Pony and perform adfraud...
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Début 2013, avant que le code malveillant Carbanak (alias Anunak, Sekur) ne soit développé, le groupe cybercriminel aurait souscrit à des Malware-as-a-Service, tels qu’Andromeda (alias Gamarue) et Pony.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
...les aurait distribués par point d’eau via le kit d’exploitation Neutrino.
successfully used the infamous Microsoft MDAC RDS.Dataspace ActiveX vulnerability to exploit the browser and drop the payload.
Many entries mention .bat, .cmd, or batch scripting, such as APT1 using batch scripting to automate execution, APT41 using a batch file for persistence, and numerous malware families executing or downloading batch files.
When users open one of these documents, the macros download and install Nymaim.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
...les aurait distribués par point d’eau via le kit d’exploitation Neutrino.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The DLL is downloaded to heap memory, written directly into the Hancitor process (using VirtualAllocEx and WriteProcessMemory) and executed from there using the CreateThread Windows API.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Examples include 'Bazar can also check if the Russian language is installed,' 'DropBook has checked for the presence of Arabic language,' 'Maze has checked the language of the infected system,' and 'SynAck ... checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.'
Blockchain-based C&C is the next step in a long evaluation of criminal TTPs, but it will be very difficult to mitigate this technique in the future
Advertising C&C Information via the Blockchain ... Fetch the last two payments from a specific bitcoin wallet ... Three Main Angles for Yesterday’s Mitigation ... Nobody can remove transactions from the blockchain.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
328 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
75 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another malware family using similar infrastructure architecture; not central to the Diamotrix analysis.
Pony is mentioned only as malware with which IcedID shared some code.
Credential/infostealer dropped alongside Raspberry Robin by a fake crack/keygen SFX installer.
Credential-stealing malware used by the TMT gang to collect saved authentication data from infected hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.