logo

PONY | FAREIT. Stealer, Loader, and Botnet.

ID: 4aa480b9-b689-58cb-b3e9-0e5a8d87f8d3

STIX ID: report--4aa480b9-b689-58cb-b3e9-0e5a8d87f8d3

Feed Name: infostealers.com

Threat Score
72/100

Date Published: 2024-02-05

Date Updated: 2026-04-28

Author: InfoStealers

...
...

Pony (Fareit/Siplog) is a long-lived loader/stealer and botnet malware; this report provides a detailed technical analysis of its infection vectors (phishing, exploit kits, fake downloads), runtime behavior (module extraction, self- and cross-process injection, UPX-packed payloads), persistence via auxiliary files and registry Run keys, anti-analysis checks, and data exfiltration targets (FTP clients, browsers, email clients). The author includes sample IOCs, typical C2 panel paths, detection opportunities mapped to ATT&CK techniques, and notes on actor usage and underground market activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.