Last seven days
- First activity
- Jul 15, 2026
- Last activity
- Jul 20, 2026
- Feed role
- C2
- Host form
- 0 IP / 3 hostnames
Pony, also known as Fareit and Siplog, is a long-running commodity malware family categorized primarily as a loader and information stealer, and it has also been described as functioning as a botnet tool.
Profile source: Mallory opens in a new tabPony
Pony, also known as Fareit and Siplog, is a long-running commodity malware family categorized primarily as a loader and information stealer, and it has also been described as functioning as a botnet tool. It has remained active for more than a decade and has been used both to steal credentials and other information and to deliver additional malware during attacks. The leaked Pony source code reportedly contributed to its broad adoption by both organized and less organized criminal actors.
Pony is commonly delivered through phishing and spearphishing attachments, including archives and documents, as well as compromised web pages, fake software downloads, exploit kits, and other malware delivery chains. The content specifically notes delivery via Hancitor, RockLoader, H1N1, Bedep, and campaigns involving CVE-2015-0311 and CVE-2017-11882. It has also appeared in campaigns alongside HawkEye and has been used by Nigerian BEC actors tracked as SilverTerrier and by the Nigerian TMT group. The content also associates Pony use with Cobalt Group, TA505, and TA544.
Technically, many analyzed Pony samples are .NET binaries that extract embedded secondary modules at runtime. Reported behaviors include anti-analysis checks for sandbox and virtualized environments, inspection of running processes for analysis or security tools, self-copying, auxiliary file launch, batch-file self-deletion, and persistence via registry keys including HKCU\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Load, HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run, and HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce. Pony has been observed injecting into or hollowing processes, including .NET-related processes such as vbc.exe, AppLaunch.exe, MSBuild.exe, installutil.exe, regasm.exe, aspnet_compiler.exe, and regsvcs.exe. It has also used NetUserEnum to enumerate local accounts.
Its payload establishes command-and-control communications and steals data by reading configuration files and Windows registry entries. The malware targets credentials and data from FTP clients, browsers, and email software, including WinSCP, FileZilla, WS_FTP, Opera, Mozilla, Chrome, Windows Live Mail, PocoMail, and BatMail. The same network channel can be used to deploy additional malware or maintain remote control. Pony command-and-control panels have frequently been hosted on previously compromised legitimate websites, complicating infrastructure tracking.
High-confidence indicators mentioned in the content include SHA-256 hashes 1a1dc33fae444afdd54f6f50dd47ed4b9f673fbc5595dad7b48e78cac0458465 and 6a581c0c07ceb888ea418fccffd5efba33b9fd6561be1bcf90b0d6ba4deefd05.
C2 tracking
Derp observations, rolling seven-day window
Samples
b9622cc44be9b2902beb1c399bcb15b6ee711d6d72ca1a9e82e96e957c231fe2 3ab0c58f330345f3dae67a4f68a4b1b4e4b8ae975aa82d90f9b013200ed4f8b0 75911dc6fa5d482feb87fb96a1e2733395312459aa9096e2e78f54bb1090a7f4 e98f6a17fd2c3926f435e4a4ddf8954250a383d7485ab5c74609916ec4dfc63d 49e3dd606bf5bf7e1c49b26a25135b2be18ee75c7b8e751c3dc538c0043e5a3f d68d7fc41cf91b92f61f84b5e055e451c013fd0180404c6b0021a7526e6788f3 Reported operators
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
The info stealers most popular with SilverTerrier last year were LokiBot (446 unique samples/month), Pony (330 unique samples/month), and Agent Tesla .NET keylogger (95 unique samples/month).
The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.
Exploited software
MITRE ATT&CK
Reporting
Pony is a good example, as it frequently follows the same architectural model.
Once one of them is executed, 3 malware samples are dropped: two stealers (Pony and AZORULT) and Raspberry Robin.
The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.
Pony used on campaigns with HawkEye
Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.
In its first years, Hancitor was observed delivering information stealers such as Pony or Vawtrak...
CVE-2017-11882 ... Products Associated Malware: Loki, FormBook, Pony/FAREIT
Credential Stealers: As in 2017, credential stealers were still accounting for the most significant amount of botnet C&C traffic; however there were changes as to which were top of the leader board. Pony held the #1 spot for two years, however in 2018 Loki took pole position...
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.