NBot is a Windows denial-of-service bot associated with the Animal Farm malware toolkit, also linked in public reporting to the SNOWGLOBE operation. It was active roughly from 2010 to 2012 and appears to have been one component of a broader malware ecosystem that also included Babar, Bunny, Casper, Tafacalou, and Dino. Unlike the more espionage-focused implants in that cluster, NBot is characterized primarily as a botnet-style malware family built to conduct network flooding operations rather than intelligence collection.
Its core functionality supports distributed denial-of-service activity using multiple protocols and request types, including plain TCP flooding and HTTP GET and POST floods with configurable behavior. Reported samples communicated with command-and-control infrastructure over clear-text HTTP and used process injection into a Windows system process via remote thread creation. Analysis has also noted dynamic API resolution through a custom hashing routine and configuration artifacts suggesting code-base overlap with Tafacalou, reinforcing assessments that it was developed by the same operator behind other Animal Farm tooling.
NBot has not been reported to include the reconnaissance, credential theft, or data exfiltration capabilities seen in the cluster’s espionage implants. Its role appears to have been operational disruption through DDoS, complementing other malware families used by the same actor for access, validation, reconnaissance, and full-featured espionage. The broader Animal Farm operator has been reported to target government entities, military contractors, humanitarian organizations, private companies, journalists, media organizations, and activists across multiple countries.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
NBot – malware used in a botnet-style operation by the group. It has DDoS capabilities.
Marquis-Boire et al. [74] use the smallest dataset containing only three samples (NBOT, Bunny and Babar) which they claim belong to the APT group named Snowglobe.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
As a means of stealth, the bots create an svchost.exe process and inject a remote thread to execute their binary payload in the context of svchost.exe... The Babar implant will inject itself into a randomly chosen desktop process... Casper infector spawns a svchost.exe process and injects its malicious payload.
As a means of stealth, the bots create an svchost.exe process and inject a remote thread to execute their binary payload in the context of svchost.exe... The Babar implant will inject itself into a randomly chosen desktop process... Casper infector spawns a svchost.exe process and injects its malicious payload.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of several implants in the Animal Farm toolkit, but not discussed further in this reference.
Malware used by Animal Farm in botnet-style operations with DDoS capability.
Denial-of-service bot with HTTP-based C2, process injection into svchost.exe, dynamic API loading, self-update capability, and multiple flooding actions including TCP, HTTP GET/POST, and ASP flooding.
Mentioned as one of three malware samples in a small research dataset.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.