Bunny is a Windows malware family associated with the Animal Farm espionage toolkit, a cluster of implants also including Babar, Dino, Casper, NBot, and Tafacalou. It has been described as an older validator-style Trojan and as a multi-threaded bot with an embedded Lua 5.1 scripting engine, allowing operators to download and execute Lua scripts to modify functionality at runtime and introduce polymorphic behavior. Bunny is linked to targeted intrusion activity against a broad range of victims, including government entities, military contractors, humanitarian organizations, private companies, journalists, media organizations, and activists.
Bunny was observed in a spearphishing campaign in late 2011 in which a malicious PDF exploited CVE-2011-4369 to install the malware. Its behavior includes anti-analysis checks aimed at emulators and sandboxes, environmental awareness such as checking process counts and hooked timing APIs, and WMI-based enumeration of installed antivirus products so that infection behavior can be adapted to the host. The family uses encrypted XML configuration data for command-and-control settings and can retrieve remote tasking in the form of Lua scripts.
Within the broader Animal Farm ecosystem, Bunny appears to have served as a flexible, scriptable implant used in targeted operations, distinct from the more fully featured Babar and Dino espionage platforms but sharing development lineage and operational tradecraft with them. Reported overlaps across the toolkit include common configuration approaches, code and technique reuse, and infrastructure patterns consistent with a coordinated state-grade espionage capability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Bunny was seen being spread in a spear-phishing campaign in December 2011, in which a PDF document exploiting CVE-2011-4369 was used to install the malware. | The second identified family was Bunny, a multi-threaded bot with an integrated scripting engine... Bunny incorporates a Lua interpreter and downloads and executes Lua scripts to reach a certain level of polymorphism. Bunny was seen being spread in a spear-phishing campaign in December 2011, in which a PDF document exploiting CVE-2011-4369 was used to install the malware.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Bunny – an old “validator”-style Trojan used with a PDF zero-day attack in 2011.
Alrabaee et al. [4] obtain malware from their own Security Lab (Zeus and Citadel malware), from Contagio (Flame and Stuxnet malware) and from VirusSign (Bunny and Babar malware).
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The bot supports a total of 20 commands... Can install managed tasks (named ‘crontask’) for its integrated engine.
The bot supports a total of 20 commands... Can install managed tasks (named ‘crontask’) for its integrated engine.
As a means of stealth, the bots create an svchost.exe process and inject a remote thread to execute their binary payload in the context of svchost.exe... The Babar implant will inject itself into a randomly chosen desktop process... Casper infector spawns a svchost.exe process and injects its malicious payload.
As a means of stealth, the bots create an svchost.exe process and inject a remote thread to execute their binary payload in the context of svchost.exe... The Babar implant will inject itself into a randomly chosen desktop process... Casper infector spawns a svchost.exe process and injects its malicious payload.
Bunny shows a number of interesting anti-analysis features, most of which seem intended for evasion of anti-virus engine emulators and sandboxes.
Using the EnumProcesses API, Bunny checks whether fewer than 15 processes are running on the system. If that is the case, execution is aborted... Bunny performs hook detection on time retrieval APIs... if any of the three deltas is below 998 milliseconds, execution will abort.
The dropped implant is not started by the dropper, merely a registry key for loading at boot time is created.
Bunny shows a number of interesting anti-analysis features, most of which seem intended for evasion of anti-virus engine emulators and sandboxes.
Using the EnumProcesses API, Bunny checks whether fewer than 15 processes are running on the system. If that is the case, execution is aborted... Bunny performs hook detection on time retrieval APIs... if any of the three deltas is below 998 milliseconds, execution will abort.
The bots connect to a C&C server and exchange data in clear text via HTTP... All three of these URLs served as C&C contacts, sending commands or Lua scripts to the infected host... Babar comes with two hard-coded C&C server domains.
All three of these URLs served as C&C contacts, sending commands or Lua scripts to the infected host... Can send and receive files via HTTP... Plainly spoken, Casper is reconnaissance malware aiming to gather sensitive information about the target system and loading second-stage malware should the target be of interest.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of several implants in the Animal Farm toolkit, but not discussed further in this reference.
An older validator-style Trojan used by the Animal Farm group, including in a PDF zero-day attack in 2011.
Multi-threaded scripted backdoor/bot with an embedded Lua interpreter, anti-analysis checks, AV-aware infection strategies, HTTP/FTP file transfer, scheduled task support, encrypted communications, and runtime behavior changes via downloaded Lua scripts.
Mentioned as malware included in a prior research dataset.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.