📣 Send us your press release
Site updates every 15 minutes
Technology

Pony Malware Steals Stored Credentials and Downloads Payloads

Picus Security has analyzed Pony malware, a threat that steals stored user credentials and delivers additional malicious software.

26 July 2026
Pony Malware Steals Stored Credentials and Downloads Payloads
Image is an AI-generated illustration

Picus Security has released an analysis of Pony malware, also known as Fareit and Siplog. Active since 2011, this threat combines credential-stealing capabilities with a downloader function, allowing for the deployment of additional malware onto compromised systems.

The widespread use of Pony is attributed to its leaked source code and an accessible builder tool, "Pony Builder." These resources enable even technically less sophisticated actors to customize and deploy variants while evading detection.

Pony targets stored credentials from web browsers, FTP clients, email programs, and SSH applications. It also employs a dictionary-based attack to brute-force local Windows account passwords. The harvested data is then transmitted to an attacker-controlled server.

Following data exfiltration, Pony downloads and executes secondary payloads, such as the Zeus banking trojan, before deleting itself to hinder forensic investigation. The Picus Platform offers capabilities to test security controls against such threats.

Original source: picussecurity.com