PONY | FAREIT. Stealer, Loader, and Botnet.
ID: 4aa480b9-b689-58cb-b3e9-0e5a8d87f8d3
STIX ID: report--4aa480b9-b689-58cb-b3e9-0e5a8d87f8d3
Feed Name: infostealers.com
Pony (Fareit/Siplog) is a long-lived loader/stealer and botnet malware; this report provides a detailed technical analysis of its infection vectors (phishing, exploit kits, fake downloads), runtime behavior (module extraction, self- and cross-process injection, UPX-packed payloads), persistence via auxiliary files and registry Run keys, anti-analysis checks, and data exfiltration targets (FTP clients, browsers, email clients). The author includes sample IOCs, typical C2 panel paths, detection opportunities mapped to ATT&CK techniques, and notes on actor usage and underground market activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
