Pony, also known as Fareit and Siplog, is a long-running commodity malware family categorized primarily as a loader and information stealer, and it has also been described as functioning as a botnet tool. It has remained active for more than a decade and has been used both to steal credentials and other information and to deliver additional malware during attacks. The leaked Pony source code reportedly contributed to its broad adoption by both organized and less organized criminal actors.
Pony is commonly delivered through phishing and spearphishing attachments, including archives and documents, as well as compromised web pages, fake software downloads, exploit kits, and other malware delivery chains. The content specifically notes delivery via Hancitor, RockLoader, H1N1, Bedep, and campaigns involving CVE-2015-0311 and CVE-2017-11882. It has also appeared in campaigns alongside HawkEye and has been used by Nigerian BEC actors tracked as SilverTerrier and by the Nigerian TMT group. The content also associates Pony use with Cobalt Group, TA505, and TA544.
Technically, many analyzed Pony samples are .NET binaries that extract embedded secondary modules at runtime. Reported behaviors include anti-analysis checks for sandbox and virtualized environments, inspection of running processes for analysis or security tools, self-copying, auxiliary file launch, batch-file self-deletion, and persistence via registry keys including HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load, HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, and HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce. Pony has been observed injecting into or hollowing processes, including .NET-related processes such as vbc.exe, AppLaunch.exe, MSBuild.exe, installutil.exe, regasm.exe, aspnet_compiler.exe, and regsvcs.exe. It has also used NetUserEnum to enumerate local accounts.
Its payload establishes command-and-control communications and steals data by reading configuration files and Windows registry entries. The malware targets credentials and data from FTP clients, browsers, and email software, including WinSCP, FileZilla, WS_FTP, Opera, Mozilla, Chrome, Windows Live Mail, PocoMail, and BatMail. The same network channel can be used to deploy additional malware or maintain remote control. Pony command-and-control panels have frequently been hosted on previously compromised legitimate websites, complicating infrastructure tracking.
High-confidence indicators mentioned in the content include SHA-256 hashes 1a1dc33fae444afdd54f6f50dd47ed4b9f673fbc5595dad7b48e78cac0458465 and 6a581c0c07ceb888ea418fccffd5efba33b9fd6561be1bcf90b0d6ba4deefd05.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2017-11882 ... Products Associated Malware: Loki, FormBook, Pony/FAREIT | CVE-2017-11882 ... Associated Malware: Loki, FormBook, Pony/FAREIT | CVE-2017-11882 Vulnerable Products: Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 Products Associated Malware: Loki, FormBook, Pony/FAREIT
CVE-2015-0311 (Flash up to 16.0.0.287) integrating Exploit Kits Patched with Flash 16.0.0.296 ... first seen exploited by Angler EK ... soon after used in standalone mode in huge malvert campaign ... integrated today in RIG ... Fiesta ... Nuclear Pack ... Sweet Orange ... Neutrino ... Magnitude | ...Bedep (doing adfraud and grabbing malware : Pony mostly from what I saw)... CVE-2015-0311 used in standalone mode to drop Bedep grab Pony and perform adfraud...
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
attacked web pages have been seen where download links have been replaced by a Fareit loader or directly the execution of it
It has typically been seen in phishing campaigns where a typical message in the language of the targeted country was introduced, simulating some kind of urgency
The content repeatedly describes threat actors and malware being delivered through phishing or spearphishing emails containing malicious attachments such as Microsoft Office documents, PDFs, RAR/ZIP archives, CHM, ISO, IMG, HTA, LNK, and executable files disguised as documents.
APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. Blue Mockingbird has used batch script files to automate execution and deployment of payloads. During HomeLand Justice, threat actors used Windows batch files for persistence and execution.
Execution [TA0002][T1059.005] Loader in VBS of pony executed via wscript
CVE-2015-0311 has been first seen exploited by Angler EK ... soon after used in "standalone" mode in huge malvert campaign ... CVE-2015-0311 has been integrated today in RIG ... Fiesta successfully exploit Windows XP IE8 Flash 16.0.0.257 using CVE-2015-0311 ... Nuclear Pack successfully exploit ... using CVE-2015-0311 ... Sweet Orange firing exploit for CVE-2015-0311 ... Neutrino firing his bundle of Sploit ... Magnitude - CVE-2015-0311 exploited successfully
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
To keep them under the antivirus radar, Nigerian actors techniques use "crypters" - software tools designed to encrypt, obfuscate, and modify malware.
Pony has also been notorious in exploit kits or in fake programs where trying to download the free version of something would gift you with a malware disguised as a small horse
The info stealers most popular with SilverTerrier last year were LokiBot (446 unique samples/month), Pony (330 unique samples/month), and Agent Tesla .NET keylogger (95 unique samples/month).
Information stealers seem to be the preferred type of malware to help in their fraudulent email attacks... The attacker can pilfer data about the targets and use it to create efficient messages for diverting transactions or asking money to be sent to fraudsters' account.
it involves capturing running processes and seeing if any of them are related to tools it doesn’t like
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
it has various basic Anti-Sandbox and Anti-VM techniques, which ultimately involve making requests to know the video controller we have. If we are emulating a machine, they will typically have strings from VirtualBox or VMWARE
Examples include "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "DropBook has checked for the presence of Arabic language," and "Maze has checked the language of the infected system using the GetUSerDefaultUILanguage function."
This code is responsible for establishing communication with the C&C
290 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
42 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another malware family using similar infrastructure architecture; not central to the Diamotrix analysis.
Credential/infostealer dropped alongside Raspberry Robin by a fake crack/keygen SFX installer.
Credential-stealing malware used by the TMT gang to collect saved authentication data from infected hosts.
Mentioned as another malware used in campaigns alongside HawkEye.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.