APTMembers
APT

A Decade-Old Fareit/Pony Stealer Still Fires the Same Signatures

A Windows executable flagged by 67 of 76 engines carries the Fareit/Tepfer/Pony stealer signature, triggering three named YARA rules and ten intrusion-detection hits on outbound checkin traffic first signatured over a decade ago. The malware itself is old news — what's kept it alive is infrastructure that keeps rotating underneath it.

Sep 26, 2026, 14:33 (UTC+9)Last seenSep 26, 2026Severity77ByCTX TeamActorGorgon GroupSubaatIOC9MITRE27RegionsRO

A Windows executable flagged by 67 of 76 engines checks in over HTTP using traffic patterns that intrusion-detection vendors have signatured for more than ten years — not because the operators built something new, but because they didn't need to. The file (hash prefix 8feae039…) carries the threat label trojan.fareit/tepfer and the popular names fareit, tepfer, and stealer, and it fires three named YARA rules, including Elastic Security's Windows_Trojan_Pony_d5516fe8 and the Malpedia signature…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence