Pony
MITRE ATT&CK: S0453 View on attack.mitre.org
Aliases: Fareit, Siplog, Pony
- First seen
- 2013-01-01 00:00:00
- Malware type
- credential-stealer, downloader, loader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 9028 (6708 malicious)
- Last IoC activity
- 2026-09-02 02:37:43
- Profile updated
- 2026-07-07 12:57:35
Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality government-and-public-sector
Context
Pony is a credential stealing malware, though has also been used among adversaries for its downloader capabilities. The source code for Pony Loader 1.0 and 2.0 were leaked online, leading to their use by various threat actors.
Recent IoC activity
6,709 malicious indicators in Maltiverse are attributed to Pony (S0453). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | www.megaretail.cl | 2026-09-03 | 1 |
| hostname | a0170719.xsph.ru | 2026-09-03 | 1 |
| hostname | gamestoredownload.download | 2026-09-03 | 4 |
| hostname | mpsound.eu | 2026-09-03 | 2 |
| hostname | www.fredlund.nu | 2026-09-03 | 1 |
| hostname | c.lewd.se | 2026-09-03 | 1 |
| hostname | sariincofood.co.id | 2026-09-03 | 2 |
| hostname | tankionlinecheats.zzz.com.ua | 2026-09-03 | 3 |
| hostname | lavorwash.mx | 2026-09-03 | 2 |
| hostname | efsec.net | 2026-09-03 | 4 |
| hostname | tsiexpressinc.com | 2026-09-03 | 2 |
| hostname | collectcoins.net | 2026-09-03 | 1 |
| hostname | sistemacplus.com.br | 2026-09-03 | 3 |
| hostname | kocdestek.redirectme.net | 2026-09-03 | 2 |
| hostname | worldbiggestsocialnetwork.in | 2026-09-03 | 1 |
| hostname | grupoalfra.cl | 2026-09-03 | 2 |
| hostname | servioficina.es | 2026-09-03 | 1 |
| hostname | mceneryfinancial.com | 2026-09-03 | 1 |
| hostname | newstarmachinery.com | 2026-09-03 | 2 |
| hostname | aldierifs.com | 2026-09-03 | 2 |
Detection coverage
- 2 YARA rules
- 289 Sigma rules
Malware & tools used
- Malicious File (attack-pattern)
- Compression (attack-pattern)
- Masquerading (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Windows Command Shell (attack-pattern)
- Junk Code Insertion (attack-pattern)
- Spearphishing Link (attack-pattern)
- System Information Discovery (attack-pattern)
- Time Based Checks (attack-pattern)
- Malicious Link (attack-pattern)
- Web Protocols (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Local Account (attack-pattern)
- Password Guessing (attack-pattern)
- File Deletion (attack-pattern)
- Native API (attack-pattern)
Detection rules
- CAPE_Fareit (yara-rule)
- MALPEDIA_Win_Pony_Auto (yara-rule)
Reports & references
- secureworks.com — Gold Essex (report)
- secureworks.com — Gold Evergreen (report)
- secureworks.com — Gold Galleon How A Nigerian Cyber Crew Plunders The Shipping Industry (report)
- secureworks.com — Gold Galleon (report)
- ESET — Eset Threat Report Q22020 (report)
- ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
- blog.intel471.com — A Brief History Of Ta505 (report)
- intel471.com — A Brief History Of Ta505 (report)
- research.checkpoint.com — Foxit Pdf Flawed Design Exploitation (report)
- spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
- secureworks.com — Gold Galleon (report)
- youtube.com — Watch (report)
- research.checkpoint.com — Select Code Execution From Using Sqlite (report)
- youtube.com — Watch (report)
- i.blackhat.com — As21 Taniguchi How Did The Adversaries Abusing The Bitcoin Blockchain Evade Our Takeover (report)
- secureworks.com — Gold Evergreen (report)
- secureworks.com — Gold Essex (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Pony (report)
- knowbe4.com — Pony Stealer (report)
- McAfee — Rp Quarterly Threats Jun 2017 (report)
- uperesia.com — Analysis Of A Packed Pony Downloader (report)
- github.com — Pony (report)
- youtube.com — Watch (report)
- int0xcc.svbtle.com — Practical Threat Hunting And Incidence Response A Case Of A Pony Malware Infection (report)
- MITRE ATT&CK — S0453 (report)