Downloader.Pony is a malware family described by Spamhaus as a dropper and credential stealer. In Spamhaus botnet-controller rankings, it was the top malware family associated with detected C2 infrastructure in both 2016 and 2017, with 602 C&Cs in 2016 and 1,015 in 2017. The reporting places it in the broader botnet ecosystem used for credential theft and retrieval of stolen data. The provided content does not specify a distinct infection vector, targeted industries, or named threat actor attribution for Downloader.Pony. No concrete indicators of compromise are provided beyond its association with botnet command-and-control infrastructure and the family name/alias Downloader.Pony.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family associated with botnet controllers, described as a dropper and credential stealer.
Malware associated with botnet controllers; described as a dropper and credential stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.