Pony

MITRE ATT&CK: S0453 View on attack.mitre.org

Aliases: Fareit, Siplog, Pony

First seen
2013-01-01 00:00:00
Malware type
credential-stealer, downloader, loader
Family
Malware family
Operating systems
windows
Related IoCs
9028 (6708 malicious)
Last IoC activity
2026-09-02 02:37:43
Profile updated
2026-07-07 12:57:35

Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality government-and-public-sector

Context

Pony is a credential stealing malware, though has also been used among adversaries for its downloader capabilities. The source code for Pony Loader 1.0 and 2.0 were leaked online, leading to their use by various threat actors.

Recent IoC activity

6,709 malicious indicators in Maltiverse are attributed to Pony (S0453). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname www.megaretail.cl 2026-09-03 1
hostname a0170719.xsph.ru 2026-09-03 1
hostname gamestoredownload.download 2026-09-03 4
hostname mpsound.eu 2026-09-03 2
hostname www.fredlund.nu 2026-09-03 1
hostname c.lewd.se 2026-09-03 1
hostname sariincofood.co.id 2026-09-03 2
hostname tankionlinecheats.zzz.com.ua 2026-09-03 3
hostname lavorwash.mx 2026-09-03 2
hostname efsec.net 2026-09-03 4
hostname tsiexpressinc.com 2026-09-03 2
hostname collectcoins.net 2026-09-03 1
hostname sistemacplus.com.br 2026-09-03 3
hostname kocdestek.redirectme.net 2026-09-03 2
hostname worldbiggestsocialnetwork.in 2026-09-03 1
hostname grupoalfra.cl 2026-09-03 2
hostname servioficina.es 2026-09-03 1
hostname mceneryfinancial.com 2026-09-03 1
hostname newstarmachinery.com 2026-09-03 2
hostname aldierifs.com 2026-09-03 2

Detection coverage

  • 2 YARA rules
  • 289 Sigma rules

Malware & tools used

  • Malicious File (attack-pattern)
  • Compression (attack-pattern)
  • Masquerading (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Junk Code Insertion (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Time Based Checks (attack-pattern)
  • Malicious Link (attack-pattern)
  • Web Protocols (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Local Account (attack-pattern)
  • Password Guessing (attack-pattern)
  • File Deletion (attack-pattern)
  • Native API (attack-pattern)

Detection rules

  • CAPE_Fareit (yara-rule)
  • MALPEDIA_Win_Pony_Auto (yara-rule)

Reports & references

  • secureworks.com — Gold Essex (report)
  • secureworks.com — Gold Evergreen (report)
  • secureworks.com — Gold Galleon How A Nigerian Cyber Crew Plunders The Shipping Industry (report)
  • secureworks.com — Gold Galleon (report)
  • ESET — Eset Threat Report Q22020 (report)
  • ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
  • blog.intel471.com — A Brief History Of Ta505 (report)
  • intel471.com — A Brief History Of Ta505 (report)
  • research.checkpoint.com — Foxit Pdf Flawed Design Exploitation (report)
  • spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
  • secureworks.com — Gold Galleon (report)
  • youtube.com — Watch (report)
  • research.checkpoint.com — Select Code Execution From Using Sqlite (report)
  • youtube.com — Watch (report)
  • i.blackhat.com — As21 Taniguchi How Did The Adversaries Abusing The Bitcoin Blockchain Evade Our Takeover (report)
  • secureworks.com — Gold Evergreen (report)
  • secureworks.com — Gold Essex (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Pony (report)
  • knowbe4.com — Pony Stealer (report)
  • McAfee — Rp Quarterly Threats Jun 2017 (report)
  • uperesia.com — Analysis Of A Packed Pony Downloader (report)
  • github.com — Pony (report)
  • youtube.com — Watch (report)
  • int0xcc.svbtle.com — Practical Threat Hunting And Incidence Response A Case Of A Pony Malware Infection (report)
  • MITRE ATT&CK — S0453 (report)

External references