Skip to content
Malware family

Pony

Pony, also known as Fareit and Siplog, is a long-running commodity malware family categorized primarily as a loader and information stealer, and it has also been described as functioning as a botnet tool.

Profile source: Mallory opens in a new tab

Pony

Family profile

Pony, also known as Fareit and Siplog, is a long-running commodity malware family categorized primarily as a loader and information stealer, and it has also been described as functioning as a botnet tool. It has remained active for more than a decade and has been used both to steal credentials and other information and to deliver additional malware during attacks. The leaked Pony source code reportedly contributed to its broad adoption by both organized and less organized criminal actors.

Pony is commonly delivered through phishing and spearphishing attachments, including archives and documents, as well as compromised web pages, fake software downloads, exploit kits, and other malware delivery chains. The content specifically notes delivery via Hancitor, RockLoader, H1N1, Bedep, and campaigns involving CVE-2015-0311 and CVE-2017-11882. It has also appeared in campaigns alongside HawkEye and has been used by Nigerian BEC actors tracked as SilverTerrier and by the Nigerian TMT group. The content also associates Pony use with Cobalt Group, TA505, and TA544.

Technically, many analyzed Pony samples are .NET binaries that extract embedded secondary modules at runtime. Reported behaviors include anti-analysis checks for sandbox and virtualized environments, inspection of running processes for analysis or security tools, self-copying, auxiliary file launch, batch-file self-deletion, and persistence via registry keys including HKCU\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Load, HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run, and HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce. Pony has been observed injecting into or hollowing processes, including .NET-related processes such as vbc.exe, AppLaunch.exe, MSBuild.exe, installutil.exe, regasm.exe, aspnet_compiler.exe, and regsvcs.exe. It has also used NetUserEnum to enumerate local accounts.

Its payload establishes command-and-control communications and steals data by reading configuration files and Windows registry entries. The malware targets credentials and data from FTP clients, browsers, and email software, including WinSCP, FileZilla, WS_FTP, Opera, Mozilla, Chrome, Windows Live Mail, PocoMail, and BatMail. The same network channel can be used to deploy additional malware or maintain remote control. Pony command-and-control panels have frequently been hosted on previously compromised legitimate websites, complicating infrastructure tracking.

High-confidence indicators mentioned in the content include SHA-256 hashes 1a1dc33fae444afdd54f6f50dd47ed4b9f673fbc5595dad7b48e78cac0458465 and 6a581c0c07ceb888ea418fccffd5efba33b9fd6561be1bcf90b0d6ba4deefd05.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 15, 2026
Last activity
Jul 20, 2026
Feed role
C2
Host form
0 IP / 3 hostnames

Leading locations

  • CY1
  • DE1

Leading providers

  • Hetzner Online GmbH1
  • Hostinger International Limited1

Infrastructure traits

  • Hosting 2
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

10 named in public reporting
TA505

Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.

TA544

Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.

GOLD EVERGREEN

Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.

Cobalt Group

Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.

GOLD ESSEX

Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.

GOLD GALLEON

Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.

GracefulSpider

Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.

NarwhalSpider

Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.

SilverTerrier

The info stealers most popular with SilverTerrier last year were LokiBot (446 unique samples/month), Pony (330 unique samples/month), and Agent Tesla .NET keylogger (95 unique samples/month).

TMT

The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.

Exploited software

Vulnerabilities linked to Pony

2 CVEs

MITRE ATT&CK

Pony in ATT&CK

36 distinct techniques

Reporting

Research mentioning Pony

Jun 3
Rexorvc0

Diamotrix | RexorVc0

Pony is a good example, as it frequently follows the same architectural model.

Mar 4
Harfanglab Insidethelab

Raspberry Robin and its new anti-emulation trick - HarfangLab

Once one of them is executed, 3 malware samples are dropped: two stealers (Pony and AZORULT) and Raspberry Robin.

Dec 27
Group Ib

Falcon: Operation in two acts | Group-IB Investigation

The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.

Nov 13
Rexorvc0

HawkEye | PredatorPain | RexorVc0

Pony used on campaigns with HawkEye

Feb 4
Rexorvc0

Pony | Fareit | RexorVc0

Pony (also known as Fareit or Siplog) is a malware categorized as a loader and stealer, although it is also used as a botnet... involved in information theft or used to launch other malwares during attacks on victim infrastructures.

Jun 21
Medium Elis531989

Dissecting and automating Hancitor’s config extraction | by Eli Salem | Medium

In its first years, Hancitor was observed delivering information stealers such as Pony or Vawtrak...

May 12
Cisa Advisories

Top 10 Routinely Exploited Vulnerabilities | CISA

CVE-2017-11882 ... Products Associated Malware: Loki, FormBook, Pony/FAREIT

Apr 1
Spamhaus

Malware | Botnet C&C malware - the highs and lows of 2018 | Spamhaus

Credential Stealers: As in 2017, credential stealers were still accounting for the most significant amount of botnet C&C traffic; however there were changes as to which were top of the leader board. Pony held the #1 spot for two years, however in 2018 Loki took pole position...

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.