What is Pony Loader?
Pony Loader is a botnet controller that targets user credentials on Windows computers. It has been around since 2011, and it is a big threat for credential theft. Pony Loader is also known as Pony, Pony Stealer, and FAreIT. When a computer is infected, Pony Loader runs in the background of the computer gathering private information about the system and the users connected with that system. Pony Loader can load other malware onto the system, or steal credentials from the system and send them to its own server. You may not even know that your computer has been infected with Pony Loader, as Pony Loader may disable antivirus software, and it can sometimes be set up to terminate after credentials are stolen.
How does Pony Loader steal credentials?
Pony Loader can steal credentials from many programs including web browsers like Google Chrome, or Internet Explorer. Pony Loader can also steal credentials from FTP applications, email accounts, and cryptocurrency wallets and more. Pony Loader steals credentials by reverse-engineering passwords that were in your computer’s encrypted storage. It can also steal credentials by using brute-force attacks, where software is used to generate many consecutive credential guesses. Once the credentials are stolen, Pony Loader sends the data back to its server where the hackers can use the data to steal money from users’ bank accounts or cryptocurrency wallets. The hackers may also sell the data to any number of sources.
Netskope Threat Research Labs has detected two variants of a data theft malware named Pony Loader resident in SaaS accounts, with one looking for around 35 different crypto-currency wallet credentials. The Pony Loader malware (also referred to as Fareit), is exclusively used in phishing campaigns, ever since the crimeware source code was made available for sale in the <