Skip to content

Pony

Pony, also widely referred to as Fareit, is a Windows credential-stealing malware family commonly used to harvest stored secrets from infected systems and to support follow-on malware delivery.

Profile source: Mallory opens in a new tab

Pony

Family profile

Pony, also widely referred to as Fareit, is a Windows credential-stealing malware family commonly used to harvest stored secrets from infected systems and to support follow-on malware delivery. It has been observed stealing credentials and related account data, and is frequently characterized as an information stealer or credential-stealing Trojan. Campaign reporting also links it to secondary payload activity in broader crimeware ecosystems, including delivery by Hancitor and use in chains that subsequently fetch other malware such as Nymaim. Some reporting also notes code-sharing or lineage overlap discussions involving IcedID.

Pony has been distributed through malicious email campaigns, including spearphishing messages carrying executable attachments or weaponized documents. Observed lures include archives and document formats intended to appear trustworthy, including files disguised with familiar document icons. It has also been associated with exploitation of Microsoft Office Equation Editor vulnerability CVE-2017-11882 in spam campaigns that delivered Pony or Pony/FAREIT to vulnerable Windows hosts. In macro-based intrusion chains, victims were enticed to open malicious Word documents and enable active content, after which upstream loaders or downloaders installed Pony.

Operationally, Pony has appeared both as a standalone credential stealer and as a payload within larger malware distribution operations. It has been delivered by Hancitor in phishing campaigns, used in infection chains tied to DocuSign-themed lures, and observed in campaigns where it served as an intermediate downloader for Nymaim. Historical reporting also places Pony among malware-as-a-service offerings used by financially motivated actors. Separate ecosystem reporting associates the name with ransomware delivery contexts, but the strongest consistent characterization is as a Windows credential-stealing malware family used in commodity cybercrime operations.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 28, 2026
Last activity
Sep 1, 2026
Feed role
C2 / Distribution
Host form
0 IP / 13 hostnames

Leading locations

  • US5
  • PL1

Leading providers

  • Amazon.com, Inc.3
  • Cloudflare, Inc.2
  • Cyber_Folks S.A.1

Infrastructure traits

  • Hosting 6
  • Anycast 4

Samples

Recent associated samples

Reported operators

Threat actors

10 named in public reporting
Carbanak

Début 2013, avant que le code malveillant Carbanak (alias Anunak, Sekur) ne soit développé, le groupe cybercriminel aurait souscrit à des Malware-as-a-Service, tels qu’Andromeda (alias Gamarue) et Pony.

TA505

Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.

TA544

Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.

GOLD EVERGREEN

Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.

Cobalt Group

Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.

GOLD ESSEX

Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.

GOLD GALLEON

Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.

NarwhalSpider

Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.

SilverTerrier

The info stealers most popular with SilverTerrier last year were LokiBot (446 unique samples/month), Pony (330 unique samples/month), and Agent Tesla .NET keylogger (95 unique samples/month).

TMT

The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.

Exploited software

Vulnerabilities linked to Pony

2 CVEs

MITRE ATT&CK

Pony in ATT&CK

43 distinct techniques

Reporting

Research mentioning Pony

Dec 15
Github Web

Malware-analysis-and-Reverse-engineering/kpot2/KPOT.md at main · Dump-GUY/Malware-analysis-and-Reverse-engineering · GitHub

Researchers detailed KPOT v2.0, a commercially sold information-stealing malware strain designed to harvest credentials and sensitive data from browsers, messaging applications, email clients, VPN and RDP software, FTP clients, gaming platforms, and cryptocurrency wallets including Jaxx. The malware was marketed on underground forums at a low price point, making it accessible to a broad range of threat actors, and its targeting of wallet users highlighted the growing overlap between credential theft and cryptocurrency-focused crime. Observed delivery methods included email campaigns and exploit kits, including an RTF lure exploiting CVE-2017-11882 to launch a PowerShell-based loader that retrieved the final payload. Once executed, KPOT used encrypted strings, runtime API resolution, and an encrypted HTTP command-and-control configuration to receive tasks, exfiltrate system and credential data, and steal files matching attacker-defined rules. The analyzed variant notably used in-memory execution and no persistence, terminating after completing assigned tasks, and also checked for victims in CIS countries before exiting without infecting them.

Sep 2
Eset Welivesecurity

KryptoCibule: The multitasking multicurrency cryptostealer

ESET disclosed KryptoCibule, a previously undocumented malware family active since at least late 2018 that primarily targeted users in Czechia and Slovakia through malicious torrents posing as cracked software installers. The malware combined several cryptocurrency-focused functions: it mined coins on infected systems, monitored the clipboard to replace copied wallet addresses and redirect payments, searched for cryptocurrency wallets and related files for exfiltration, and also exposed remote-access trojan (RAT) capabilities. The campaign relied heavily on Tor and BitTorrent infrastructure and either bundled or fetched legitimate tools including Tor, Transmission, Apache httpd, and Buru SFTP Server to support command-and-control and data theft through onion services hosted on compromised machines. ESET said KryptoCibule used layered evasion and persistence measures, including obfuscation, masquerading as Adobe Reader components, scheduled tasks, Windows Defender exclusions, firewall rule changes, and checks for analysis tools and antivirus products; although only hundreds of victims were observed, the malware remained active and continued to gain new capabilities.

Apr 12
Handlers Diary Full

Reader Analysis: "Dynamic analysis technique to get decrypted KPOT Malware."

May 9
Proofpoint Threat Insight

New KPOT v2.0 stealer brings zero persistence and in-memory features to silently steal credentials | Proofpoint US

Feb 29
Proofpoint

Ransomware - Nymaim Moves Past Its Ransomware Roots | Proofpoint US

Nymaim evolved from a ransomware-associated threat into a flexible malware downloader delivered primarily through phishing emails, including campaigns that abused a legitimate bulk email marketing service to improve delivery and evade blacklist-based defenses. Victims were lured into opening malicious Word documents or links to macro-enabled files, after which Nymaim installed and frequently fetched additional payloads such as the Ursnif banking Trojan; one observed infection chain dropped Pony first and then used it to retrieve Nymaim. Researchers also noted that the malware retained web-injection capabilities aimed at banking sessions and continued to use heavy in-memory obfuscation to complicate analysis and detection. Later analysis showed Nymaim also overhauled its command-and-control resilience with a new wordlist-based domain generation algorithm (DGA) seeded by a hard-coded key and date values, producing domains across an 11-day sliding window with 64 domains per day alongside 46 hard-coded domains. The malware avoided exposing direct C2 addresses by transforming DNS A records into IPs, validating responses with a checksum mechanism, and screening NS records for sinkhole-related keywords before connecting. Once infrastructure was selected, the sample sent encrypted HTTP POST traffic to a hard-coded /index.php endpoint using AES and asymmetric encryption, underscoring Nymaim's transition into a more stealthy and resilient banking-malware delivery platform.

Jun 13
Johannesbader

The new Domain Generation Algorithm of Nymaim

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.