Babar is a Windows espionage malware platform associated with the Animal Farm intrusion set, also known as SNOWGLOBE, which has been publicly linked by multiple researchers to French state-aligned cyber operations. It has been described as one of the most sophisticated implants in that toolkit and was used as a second-stage surveillance platform after earlier validator or entry-stage components such as Tafacalou. Publicly discussed samples date from at least 2007, indicating long-term development and operational use.
Babar is designed for covert intelligence collection and remote post-compromise control. Reported capabilities include process injection, API hooking, keylogging, clipboard theft, screenshot capture, audio capture, collection of host and user profiling data, and exfiltration of stolen information to operator-controlled infrastructure. Analyses of older variants show persistence through Windows autorun mechanisms, storage of encrypted configuration and victim identifiers in the registry, injection into browser processes, and command support for downloading files, executing shell commands, listing and terminating processes, changing command-and-control parameters, rebooting or shutting down the system, and self-uninstalling. Some variants used encrypted XML configuration data and encrypted command-and-control traffic over HTTP.
Babar has been linked to a broader malware ecosystem that includes Dino, Bunny, Casper, NBot, and Tafacalou. Shared code, configuration styles, injection methods, antivirus enumeration logic, and infrastructure patterns across these families indicate coordinated development within a common espionage framework. Within that framework, Babar served as a high-value surveillance implant deployed against selected victims after initial compromise and validation.
Victimology associated with Animal Farm operations includes government entities, military contractors, humanitarian organizations, private companies, journalists, media organizations, and activists across multiple regions. Babar itself is therefore best understood as a nation-state espionage implant used in targeted intrusions rather than indiscriminate cybercrime. High-confidence reporting supports Windows as the primary platform for known Babar samples.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Babar – the most sophisticated espionage platform from the Animal Farm group.
Alrabaee et al. [4] obtain malware from their own Security Lab (Zeus and Citadel malware), from Contagio (Flame and Stuxnet malware) and from VirusSign (Bunny and Babar malware).
22 distinct techniques documented for this family, organized by ATT&CK tactic.
It contains an encrypted resource named XML which contains configuration data. The encryption algorithm RC4 is used with the key +37:*$pK#s.
This data is then used to create the following file paths with the hardcoded file names: ... \Microsoft\wmimgnt.dll ... \Microsoft\wmimgnt.exe
At last, it creates a suspended process of Internet Explorer and injects the payload DLL via the infamous CreateRemoteThread() method.
The dropped implant is not started by the dropper, merely a registry key for loading at boot time is created.
Possible malware commands: ... 19. listprocess Get list of current processes with PID
Then, it tries to get system information from the following registry keys... RegisteredOrganization ... RegisteredOwner ... CurrentVersion ... DefaultUserName ... USERNAME
The Babar implant applies a global Windows hook... Babar installs hooks for types 2 and 3, which are WH_KEYBOARD and WH_GETMESSAGE.
Babar is a fully fledged piece of espionage software... log keystrokes... A summary of the capabilities is as follows: • Logging keystrokes
Tafacalou (aka “TFC”, “Transporter”) is perhaps of greatest interest here, because it acts as an entry point for the more sophisticated spy platforms Babar and Dino. Confirmed victims get upgraded to Dino or Babar.
The sample also uses a compromised third party website as a C2 server like later versions... As can be seen, a third-party website was compromised as C2 server to host a script named outbase.php.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a generic AV family classification applied to the sample; the content explicitly warns not to attribute the analyzed sample to historical Babar activity based on AV naming alone.
Babar is a malware family, often categorized as spyware, delivered via malvertising and parked domain redirects. It is distributed through ClickFix attacks that attempt to trick users into running malicious scripts.
Referenced as malware attributed to the French government-linked Animal Farm group; mentioned only for comparison/background.
Espionage malware described in the cited sources as likely created by France and used for spying operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.