Description
Pony (a.k.a. Fareit) is an information stealer that targets credentials from browsers, FTP clients, email programs, and other applications on infected systems. It arrived through spam attachments, exploit kits, and bundled downloads, and its checker component validated stolen credentials in bulk for resale. The family's efficiency at collecting large volumes of logins made it a mainstay of the criminal credential market for years.
Stats
- First seen
- July 2024
- Last seen
- October 2026
MITRE ATT&CK techniques
16 techniques across 6 tactics.
TA0002 Execution
TA0005 Stealth
Alert name variants
| Alert Name |
|---|
| Archive.Infostealer.Pony |
| Binary.Infostealer.Pony |
| ByteCode-MSIL.Infostealer.Pony |
| Document-Word.Infostealer.Pony |
| Email-MIME.Infostealer.Pony |
| Linux.Infostealer.Pony |
| Script-AutoIt.Infostealer.Pony |
| Script-JS.Infostealer.Pony |
| Win32.Infostealer.Pony |
| Win64.Infostealer.Pony |




