Last seven days
- First activity
- Aug 28, 2026
- Last activity
- Sep 1, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 13 hostnames
Pony, also widely referred to as Fareit, is a Windows credential-stealing malware family commonly used to harvest stored secrets from infected systems and to support follow-on malware delivery.
Profile source: Mallory opens in a new tabPony
Pony, also widely referred to as Fareit, is a Windows credential-stealing malware family commonly used to harvest stored secrets from infected systems and to support follow-on malware delivery. It has been observed stealing credentials and related account data, and is frequently characterized as an information stealer or credential-stealing Trojan. Campaign reporting also links it to secondary payload activity in broader crimeware ecosystems, including delivery by Hancitor and use in chains that subsequently fetch other malware such as Nymaim. Some reporting also notes code-sharing or lineage overlap discussions involving IcedID.
Pony has been distributed through malicious email campaigns, including spearphishing messages carrying executable attachments or weaponized documents. Observed lures include archives and document formats intended to appear trustworthy, including files disguised with familiar document icons. It has also been associated with exploitation of Microsoft Office Equation Editor vulnerability CVE-2017-11882 in spam campaigns that delivered Pony or Pony/FAREIT to vulnerable Windows hosts. In macro-based intrusion chains, victims were enticed to open malicious Word documents and enable active content, after which upstream loaders or downloaders installed Pony.
Operationally, Pony has appeared both as a standalone credential stealer and as a payload within larger malware distribution operations. It has been delivered by Hancitor in phishing campaigns, used in infection chains tied to DocuSign-themed lures, and observed in campaigns where it served as an intermediate downloader for Nymaim. Historical reporting also places Pony among malware-as-a-service offerings used by financially motivated actors. Separate ecosystem reporting associates the name with ransomware delivery contexts, but the strongest consistent characterization is as a Windows credential-stealing malware family used in commodity cybercrime operations.
C2 tracking
Derp observations, rolling seven-day window
Samples
3ab0c58f330345f3dae67a4f68a4b1b4e4b8ae975aa82d90f9b013200ed4f8b0 75911dc6fa5d482feb87fb96a1e2733395312459aa9096e2e78f54bb1090a7f4 e98f6a17fd2c3926f435e4a4ddf8954250a383d7485ab5c74609916ec4dfc63d 351d0faf18a9c7ab1de84617fe0677d270b6f42368337e7d5b581241e30f48c6 884425e22b10b73211805ca7455a5de82a8189befd703bd5b9e3e46f610953c3 91001693548d2e77343744b0212982aaba6a71cfa6e98f258b0970ab88b0c086 b5ead50229b1942cb83d9d7bf42269b57b22e8576f7f7f1c047f4d23802e6bd7 feaca8bb0b15f31445f3a292d287af3ce2ff4793eaf2747a897e5543dd43985b be8d71277a3e7832ec4e94f650363dfb54f5972edf339a6603cc192439d71194 03232fdd36bbfe7006b2046c24b8a0d69f6fd7d50699a0e037330b56d7ae2153 Reported operators
Début 2013, avant que le code malveillant Carbanak (alias Anunak, Sekur) ne soit développé, le groupe cybercriminel aurait souscrit à des Malware-as-a-Service, tels qu’Andromeda (alias Gamarue) et Pony.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
The info stealers most popular with SilverTerrier last year were LokiBot (446 unique samples/month), Pony (330 unique samples/month), and Agent Tesla .NET keylogger (95 unique samples/month).
The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.
Exploited software
MITRE ATT&CK
Reporting
Researchers detailed KPOT v2.0, a commercially sold information-stealing malware strain designed to harvest credentials and sensitive data from browsers, messaging applications, email clients, VPN and RDP software, FTP clients, gaming platforms, and cryptocurrency wallets including Jaxx. The malware was marketed on underground forums at a low price point, making it accessible to a broad range of threat actors, and its targeting of wallet users highlighted the growing overlap between credential theft and cryptocurrency-focused crime. Observed delivery methods included email campaigns and exploit kits, including an RTF lure exploiting CVE-2017-11882 to launch a PowerShell-based loader that retrieved the final payload. Once executed, KPOT used encrypted strings, runtime API resolution, and an encrypted HTTP command-and-control configuration to receive tasks, exfiltrate system and credential data, and steal files matching attacker-defined rules. The analyzed variant notably used in-memory execution and no persistence, terminating after completing assigned tasks, and also checked for victims in CIS countries before exiting without infecting them.
ESET disclosed KryptoCibule, a previously undocumented malware family active since at least late 2018 that primarily targeted users in Czechia and Slovakia through malicious torrents posing as cracked software installers. The malware combined several cryptocurrency-focused functions: it mined coins on infected systems, monitored the clipboard to replace copied wallet addresses and redirect payments, searched for cryptocurrency wallets and related files for exfiltration, and also exposed remote-access trojan (RAT) capabilities. The campaign relied heavily on Tor and BitTorrent infrastructure and either bundled or fetched legitimate tools including Tor, Transmission, Apache httpd, and Buru SFTP Server to support command-and-control and data theft through onion services hosted on compromised machines. ESET said KryptoCibule used layered evasion and persistence measures, including obfuscation, masquerading as Adobe Reader components, scheduled tasks, Windows Defender exclusions, firewall rule changes, and checks for analysis tools and antivirus products; although only hundreds of victims were observed, the malware remained active and continued to gain new capabilities.
Nymaim evolved from a ransomware-associated threat into a flexible malware downloader delivered primarily through phishing emails, including campaigns that abused a legitimate bulk email marketing service to improve delivery and evade blacklist-based defenses. Victims were lured into opening malicious Word documents or links to macro-enabled files, after which Nymaim installed and frequently fetched additional payloads such as the Ursnif banking Trojan; one observed infection chain dropped Pony first and then used it to retrieve Nymaim. Researchers also noted that the malware retained web-injection capabilities aimed at banking sessions and continued to use heavy in-memory obfuscation to complicate analysis and detection. Later analysis showed Nymaim also overhauled its command-and-control resilience with a new wordlist-based domain generation algorithm (DGA) seeded by a hard-coded key and date values, producing domains across an 11-day sliding window with 64 domains per day alongside 46 hard-coded domains. The malware avoided exposing direct C2 addresses by transforming DNS A records into IPs, validating responses with a checksum mechanism, and screening NS records for sinkhole-related keywords before connecting. Once infrastructure was selected, the sample sent encrypted HTTP POST traffic to a hard-coded /index.php endpoint using AES and asymmetric encryption, underscoring Nymaim's transition into a more stealthy and resilient banking-malware delivery platform.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.