Netskope Threat Labs

Pony

ATP Sandbox Adv. HeuristicsNetskope IPS

Pony (a.k.a. Fareit) is an information stealer that targets credentials from browsers, FTP clients, email programs, and other applications on infected systems. It arrived through spam attachments, exploit kits, and bundled downloads, and its checker component validated stolen credentials in bulk for resale. The family's efficiency at collecting large volumes of logins made it a mainstay of the criminal credential market for years.

First seen
July 2024
Last seen
October 2026

16 techniques across 6 tactics.

TA0001 Initial Access

TA0002 Execution

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

TA0011 Command and Control

Alert Name
Archive.Infostealer.Pony
Binary.Infostealer.Pony
ByteCode-MSIL.Infostealer.Pony
Document-Word.Infostealer.Pony
Email-MIME.Infostealer.Pony
Linux.Infostealer.Pony
Script-AutoIt.Infostealer.Pony
Script-JS.Infostealer.Pony
Win32.Infostealer.Pony
Win64.Infostealer.Pony