Netskope Threat Labs

PonyStealer

ATP Sandbox Adv. HeuristicsAV

PonyStealer (a.k.a. Fareit) is a malware family that steals passwords from hundreds of applications, including web browsers, email clients, messaging apps, and FTP software. Its campaigns spread through phishing emails, malicious downloads, and bundled installers, and stolen credentials flow to panels where operators use or sell them. The family's broad application coverage made it one of the most productive commodity stealers of its era.

First seen
January 2022
Last seen
June 2026
Alert Name
DeepScan:Generic.PonyStealer.191A049B
DeepScan:Generic.PonyStealer.AE3455AE
DeepScan:Generic.PonyStealer.D49B4D0D
Gen:Heur.PonyStealer.MLT.1
JS:Trojan.PonyStealer.A
Win32.Infostealer.PonyStealer