Animal Farm is a nation-state cyber-espionage malware toolkit widely associated with French intelligence reporting and composed of multiple implants including Babar, Dino, Casper, Bunny, NBot, Tafacalou, Dinotransport, EvilBunny, and SnowGlobe. It is best understood as an umbrella framework rather than a single standalone implant, with different components used for long-term covert access, remote control, and intelligence collection on Windows systems.
Publicly discussed Animal Farm components show capabilities typical of mature espionage operations. Early Babar variants functioned as backdoor implants delivered through a loader-and-payload architecture, using encrypted configuration data, registry-based persistence, process injection into Internet Explorer, host profiling, and HTTP command-and-control. Documented command support included remote execution, file retrieval, process listing and termination, reboot, shutdown, configuration updates, and self-uninstall. Some variants also attempted to reduce forensic visibility by deleting user-interface execution traces and storing identifiers and configuration data in encrypted form.
Animal Farm has been referenced alongside other top-tier espionage platforms in victim environments that included research institutions and other high-value targets, indicating use against strategically significant organizations. Reporting on leaked counter-APT detection tooling has also mapped Animal Farm-related signatures to implants such as Dino, Babar, Dinotransport, EvilBunny, and SnowGlobe, reinforcing its status as a distinct multi-implant ecosystem. High-confidence public reporting supports Windows as a target platform and supports post-compromise espionage, persistence, defense evasion, process injection, and exfiltration-oriented remote access behavior within at least some Animal Farm components.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
IoCs include services such as mrxcls service, WinMI32 service, HP003044 service, NetBIOS2010 service, pnppci service, ethio service, ntdos505 service.
They check for the existence of specific files, windows registry entries, and other signs ... For example, this script looks for the existence of an actual file “winver32.exe” in the very specific $docsandsettings\\$subkey\\Application Data\\winver32.exe path.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A known nation-state espionage malware/toolkit referenced for comparison with fast16.
A malware toolkit composed of multiple implants including Babar. In this reference it serves as the broader toolkit to which Babar belongs.
Named as one of several advanced threats observed on the same research institution computer; no additional detail is provided in the content.
Mentioned as another advanced threat present on the same victim machine.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.