Pony

S0453

Malware.View on attack.mitre.org

About this malware

Pony is a credential stealing malware, though has also been used among adversaries for its downloader capabilities. The source code for Pony Loader 1.0 and 2.0 were leaked online, leading to their use by various threat actors.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1027.015
Compression

Pony attachments have been delivered via compressed archive files.

T1027.016
Junk Code Insertion

Pony obfuscates memory flow by adding junk instructions when executing to make analysis more difficult.

T1036
Masquerading

Pony has used the Adobe Reader icon for the downloaded file to look more trustworthy.

T1059.003
Windows Command Shell

Pony has used batch scripts to delete itself after execution.

T1070.004
File Deletion

Pony has used scripts to delete itself after execution.

T1071.001
Web Protocols

Pony has sent collected information to the C2 via HTTP POST request.

T1082
System Information Discovery

Pony has collected the Service Pack, language, and region information to send to the C2.

T1087.001
Local Account

Pony has used the NetUserEnum function to enumerate local accounts.

T1105
Ingress Tool Transfer

Pony can download additional files onto the infected system.

T1106
Native API

Pony has used several Windows functions for various purposes.

T1110.001
Password Guessing

Pony has used a small dictionary of common passwords against a collected list of local accounts.

T1204.001
Malicious Link

Pony has attempted to lure targets into clicking links in spoofed emails from legitimate banks.

T1204.002
Malicious File

Pony has attempted to lure targets into downloading an attached executable (ZIP, RAR, or CAB archives) or document (PDF or other MS Office format).

T1497.003
Time Based Checks

Pony has delayed execution using a built-in function to avoid detection and analysis.

T1566.001
Spearphishing Attachment

Pony has been delivered via spearphishing attachments.

View all 16 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Malwarebytes Pony April 2016 Open source
    hasherezade. (2016, April 11). No money, but Pony! From a mail to a trojan horse. Retrieved May 21, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.