Pony, also known as FAREIT, is a Windows credential-stealing trojan. It has been delivered through phishing and spearphishing campaigns using executable, archive, PDF, and Microsoft Office document attachments, including documents exploiting CVE-2017-11882 or requiring victims to enable macros. It has also been deployed as a secondary payload by Hancitor and appeared in infection chains in which it downloaded Nymaim. Pony has used deceptive file iconography to appear trustworthy and can delete itself after execution to reduce forensic evidence. It has been associated with criminal malware-distribution campaigns rather than a uniquely attributable threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Trend Micro’s initial and ongoing analysis also found that a spammer group is also actively exploiting CVE-2017-11882 to infect systems with information stealers Pony/FAREIT and FormBook.
CVE-2015-0311 (Flash up to 16.0.0.287) integrating Exploit Kits Patched with Flash 16.0.0.296 ... first seen exploited by Angler EK ... soon after used in standalone mode in huge malvert campaign ... integrated today in RIG ... Fiesta ... Nuclear Pack ... Sweet Orange ... Neutrino ... Magnitude | ...Bedep (doing adfraud and grabbing malware : Pony mostly from what I saw)... CVE-2015-0311 used in standalone mode to drop Bedep grab Pony and perform adfraud...
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Début 2013, avant que le code malveillant Carbanak (alias Anunak, Sekur) ne soit développé, le groupe cybercriminel aurait souscrit à des Malware-as-a-Service, tels qu’Andromeda (alias Gamarue) et Pony.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
...les aurait distribués par point d’eau via le kit d’exploitation Neutrino.
successfully used the infamous Microsoft MDAC RDS.Dataspace ActiveX vulnerability to exploit the browser and drop the payload.
Many entries mention .bat, .cmd, or batch scripting, such as APT1 using batch scripting to automate execution, APT41 using a batch file for persistence, and numerous malware families executing or downloading batch files.
When users open one of these documents, the macros download and install Nymaim.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
...les aurait distribués par point d’eau via le kit d’exploitation Neutrino.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The DLL is downloaded to heap memory, written directly into the Hancitor process (using VirtualAllocEx and WriteProcessMemory) and executed from there using the CreateThread Windows API.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Examples include 'Bazar can also check if the Russian language is installed,' 'DropBook has checked for the presence of Arabic language,' 'Maze has checked the language of the infected system,' and 'SynAck ... checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.'
Blockchain-based C&C is the next step in a long evaluation of criminal TTPs, but it will be very difficult to mitigate this technique in the future
Advertising C&C Information via the Blockchain ... Fetch the last two payments from a specific bitcoin wallet ... Three Main Angles for Yesterday’s Mitigation ... Nobody can remove transactions from the blockchain.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
328 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
77 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another malware family using similar infrastructure architecture; not central to the Diamotrix analysis.
Pony is mentioned only as malware with which IcedID shared some code.
Credential/infostealer dropped alongside Raspberry Robin by a fake crack/keygen SFX installer.
Credential-stealing malware used by the TMT gang to collect saved authentication data from infected hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.