Malware.View on attack.mitre.org
Pony is a credential stealing malware, though has also been used among adversaries for its downloader capabilities. The source code for Pony Loader 1.0 and 2.0 were leaked online, leading to their use by various threat actors.
| Technique | Procedure example |
|---|---|
| T1027.015 Compression |
Pony attachments have been delivered via compressed archive files. |
| T1027.016 Junk Code Insertion |
Pony obfuscates memory flow by adding junk instructions when executing to make analysis more difficult. |
| T1036 Masquerading |
Pony has used the Adobe Reader icon for the downloaded file to look more trustworthy. |
| T1059.003 Windows Command Shell |
Pony has used batch scripts to delete itself after execution. |
| T1070.004 File Deletion |
Pony has used scripts to delete itself after execution. |
| T1071.001 Web Protocols |
Pony has sent collected information to the C2 via HTTP POST request. |
| T1082 System Information Discovery |
Pony has collected the Service Pack, language, and region information to send to the C2. |
| T1087.001 Local Account |
Pony has used the |
| T1105 Ingress Tool Transfer |
Pony can download additional files onto the infected system. |
| T1106 Native API |
Pony has used several Windows functions for various purposes. |
| T1110.001 Password Guessing |
Pony has used a small dictionary of common passwords against a collected list of local accounts. |
| T1204.001 Malicious Link |
Pony has attempted to lure targets into clicking links in spoofed emails from legitimate banks. |
| T1204.002 Malicious File |
Pony has attempted to lure targets into downloading an attached executable (ZIP, RAR, or CAB archives) or document (PDF or other MS Office format). |
| T1497.003 Time Based Checks |
Pony has delayed execution using a built-in function to avoid detection and analysis. |
| T1566.001 Spearphishing Attachment |
Pony has been delivered via spearphishing attachments. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.