Netskope Threat Labs

Fareit

ATP Sandbox Adv. HeuristicsAV

Fareit (a.k.a. Siplog, Pony) is both an infostealer and a botnet, and it harvests credentials from VPN clients, FTP programs, browsers, email clients, and other applications. It typically arrives through spam email attachments and exploits, and it uploads the stolen data to panels its operators use or sell. The family's credential checker component made it a popular tool for validating bulk stolen credentials across the criminal market.

First seen
January 2022
Last seen
October 2026
Alert Name
Binary.Infostealer.Fareit
ByteCode-MSIL.Downloader.Fareit
ByteCode-MSIL.Infostealer.Fareit
Document-Multimedia.Infostealer.Fareit
Document-Word.Infostealer.Fareit
Gen:Heur.Fareit.1
Linux.Infostealer.Fareit
Trojan.Fareit.V
Trojan.PWS.Fareit.BW
Trojan.PWS.Fareit.D