Animal Farm is a long-running cyber-espionage threat actor widely assessed as linked to the French government or French intelligence services. The group has been active since at least 2009, with indications that parts of its toolset were under development as early as 2007. It is associated with a cluster of malware families including Babar, Dino, Bunny, NBot, Tafacalou, and Casper, and has also been referred to under the cryptonym SNOWGLOBE in some reporting. Babar and Dino are regarded as the group’s principal full-featured espionage platforms, while Tafacalou, Bunny, and Casper have been described as validator or entry-stage implants used to identify and prepare victims for follow-on deployment of more capable spyware. Confirmed Tafacalou infections were in some cases upgraded to Dino or Babar. Animal Farm has targeted a broad international victim set spanning government organizations, military contractors, humanitarian organizations, private-sector entities, journalists, media organizations, and activists. Reported victim geography includes countries across the Middle East, Europe, North America, Africa, and Asia, with documented activity including a watering-hole operation in Syria and an operation affecting users in Burkina Faso. The group has been linked to exploitation of multiple zero-day vulnerabilities in the wild. The actor’s tradecraft reflects mature espionage operations: staged intrusion chains, validator implants preceding higher-value payloads, long-term malware development, and use of watering-hole attacks. Its malware ecosystem includes highly capable surveillance platforms and supporting loaders and transport components. NBot has additionally been described as supporting botnet-style operations with DDoS capability, although Animal Farm is primarily characterized as an intelligence-collection actor rather than a disruptive one. Reporting has also noted Lua use in Animal Farm tooling, a relatively uncommon choice among advanced threat actors. Overall, Animal Farm is best understood as a sophisticated French state-linked espionage actor with a diverse malware arsenal and a history of targeting politically and strategically relevant organizations worldwide.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison point among publicly discussed Western government hacking groups.
Mentioned only as historical comparison for prior APT use of Lua.
Referenced as the actor behind the SNOWGLOBE cryptonym and associated with the Babar malware family.
Referenced as the actor behind the SNOWGLOBE cryptonym and associated with the Babar malware family.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.